[CLSA-2026:1788271850] Fix CVE(s): CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-01 14:11:01 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib - debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch: reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93). - CVE-2025-15367
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-4_amd64.deb
    sha:63539746b7a71ae6377c0661826eff9c13de130c
  • alt-python312-debug_3.12.14-4_amd64.deb
    sha:270c3f01aae60741e324566346a69b5319fb6305
  • alt-python312-devel_3.12.14-4_amd64.deb
    sha:424a0cba8f98b649f34055dd74bcec8d27dd6247
  • alt-python312-idle_3.12.14-4_amd64.deb
    sha:da85f0501106f6a39973b46373d64d6b06f2d25a
  • alt-python312-libs_3.12.14-4_amd64.deb
    sha:5ceef85b69d881031350138bc3d9800f43b2df8e
  • alt-python312-test_3.12.14-4_amd64.deb
    sha:e9d5537ee9aa4bc1262deb02a1fa60d554f72675
  • alt-python312-tkinter_3.12.14-4_amd64.deb
    sha:ad92b832fddffe137be97371963420b1910024b2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.