Release date:
2026-09-02 09:12:47 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib
- debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch:
reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a
user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93).
- CVE-2025-15367
Updated packages:
-
alt-python312_3.12.14-4_amd64.deb
sha:90b877681646c3a6e3f663610485d38164cd9fce
-
alt-python312-debug_3.12.14-4_amd64.deb
sha:270c3f01aae60741e324566346a69b5319fb6305
-
alt-python312-devel_3.12.14-4_amd64.deb
sha:03c55bc916337f06af3cf0ff22848ba4b68f2ba2
-
alt-python312-idle_3.12.14-4_amd64.deb
sha:da85f0501106f6a39973b46373d64d6b06f2d25a
-
alt-python312-libs_3.12.14-4_amd64.deb
sha:4456a18fe79097e1d8f96c37b26d12989828dae8
-
alt-python312-test_3.12.14-4_amd64.deb
sha:a04db11e93e4acfff9a6d2f33c0715395b1911a1
-
alt-python312-tkinter_3.12.14-4_amd64.deb
sha:71f5815faadb256e017cd227893218936b7b8866
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.