Release date:
2026-09-02 10:09:52 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib
- debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch:
reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a
user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93).
- CVE-2025-15367
Updated packages:
-
alt-python313_3.13.15-3_amd64.deb
sha:f9f14f0108c4fcac97a0406fa9ba4830e13500e8
-
alt-python313-debug_3.13.15-3_amd64.deb
sha:875d6d024c932b7e38c0fc83b728d5f5a12b475c
-
alt-python313-devel_3.13.15-3_amd64.deb
sha:fff4ad7cc32107d5ccf43fa845db3d9533568bc4
-
alt-python313-idle_3.13.15-3_amd64.deb
sha:5d4a0f46d78a771b45cf50b7e1b44f694ef1d552
-
alt-python313-libs_3.13.15-3_amd64.deb
sha:23c0d58f82f3b143f71448b1f81ac5acd955547c
-
alt-python313-test_3.13.15-3_amd64.deb
sha:d329f660acc478ac6073b413388448dbdf77242b
-
alt-python313-tkinter_3.13.15-3_amd64.deb
sha:43e56355fa90c0238852451f82055b603d01771d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.