Release date:
2026-09-02 09:25:32 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib
- debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch:
reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a
user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93).
- CVE-2025-15367
Updated packages:
-
alt-python312_3.12.14-4_amd64.deb
sha:ccafb32c3f630d4c4e4334c5c69a68707f638caf
-
alt-python312-debug_3.12.14-4_amd64.deb
sha:270c3f01aae60741e324566346a69b5319fb6305
-
alt-python312-devel_3.12.14-4_amd64.deb
sha:fc600012ba5476ed717bd9700688d285c19c3e21
-
alt-python312-idle_3.12.14-4_amd64.deb
sha:f02abcfde5b8a2f678fed37776b8e4112c3a1abf
-
alt-python312-libs_3.12.14-4_amd64.deb
sha:9a5a0dc36aed11010fa915f423a9809c41f2d0f7
-
alt-python312-test_3.12.14-4_amd64.deb
sha:cd65fb7898500e3fb09b669b4ba9a34dcd229a7e
-
alt-python312-tkinter_3.12.14-4_amd64.deb
sha:9b83bee4ec807c7d865138d631293270561cac81
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.