Release date:
2026-09-02 08:13:52 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib
- debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch:
reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a
user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93).
- CVE-2025-15367
Updated packages:
-
alt-python313_3.13.15-3_amd64.deb
sha:25e13598419bf08ac175ed01a963f5b9ef38dd00
-
alt-python313-debug_3.13.15-3_amd64.deb
sha:875d6d024c932b7e38c0fc83b728d5f5a12b475c
-
alt-python313-devel_3.13.15-3_amd64.deb
sha:d1e6567c59872b36b75c934559cea618a8a691e3
-
alt-python313-idle_3.13.15-3_amd64.deb
sha:c9acb7fd491d7275d6c2085b6fcfc9d522f8249e
-
alt-python313-libs_3.13.15-3_amd64.deb
sha:ffeedaac1b6c5f5f66b30a2b7ec0c9f7520979ac
-
alt-python313-test_3.13.15-3_amd64.deb
sha:4b858e12658c16f3f076a8505a4e77721ac4ec9e
-
alt-python313-tkinter_3.13.15-3_amd64.deb
sha:3904d61464fab5336dc968614b5cdb3fcaa79802
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.