Release date:
2026-09-03 14:07:54 UTC
Description:
* SECURITY UPDATE: control-character command injection in imaplib
- debian/patches/CVE-2025-15366.patch: reject control characters in
IMAP4._command() so user-controlled arguments cannot inject extra
IMAP commands or extra command arguments (CWE-77/CWE-93).
- CVE-2025-15366
Updated packages:
-
alt-python312_3.12.14-5_amd64.deb
sha:46a6731608b6d2041127a5604344bb95720c86c8
-
alt-python312-debug_3.12.14-5_amd64.deb
sha:2d8ff4acf34dedba3575c84ed313a2ee25a72002
-
alt-python312-devel_3.12.14-5_amd64.deb
sha:9a7d6239379110a367878f4686f8b5b05cc2923f
-
alt-python312-idle_3.12.14-5_amd64.deb
sha:a64bdab8ee7529b8138ce164dece0b39f27afd65
-
alt-python312-libs_3.12.14-5_amd64.deb
sha:bf8d5e108a39d87ad6b37d4fb499913c3541ad5c
-
alt-python312-test_3.12.14-5_amd64.deb
sha:8e77e30a073e71a77b269c269b20594948cb3ef5
-
alt-python312-tkinter_3.12.14-5_amd64.deb
sha:dee6fd2f067f3372e9ef7c39bbbbdefa09a68809
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.