[CLSA-2026:1788293034] alt-python312: Fix of CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-01 20:04:05 UTC
Description:
- CVE-2025-15367: reject control characters in poplib POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-3.el10.x86_64.rpm
    sha:978a73b467bbf7abb25f2aa314cad796fbe059b9960c3cdb3ed5d60f28a8e149
  • alt-python312-debug-3.12.14-3.el10.x86_64.rpm
    sha:5affd26ce35f1417d08ebea5d3ae79e1fca28ece15f1dcb2f3c352b2d60146d8
  • alt-python312-devel-3.12.14-3.el10.x86_64.rpm
    sha:e486649d8de51530ea0a6f43f9dfacb609a9c23d018fbd6aa176f61ec938045a
  • alt-python312-idle-3.12.14-3.el10.x86_64.rpm
    sha:3dc3eb7b2824a154b7d167bbd1b42561dbc382e40029be4de908cbd43143a4f0
  • alt-python312-libs-3.12.14-3.el10.x86_64.rpm
    sha:38a1be5db6b31ff94241fa8f8d42e5002e592d029ee13e95c78ce6020cc69d37
  • alt-python312-test-3.12.14-3.el10.x86_64.rpm
    sha:0f4055b06557ec2bc1b8a5a72d0dfa5957fac4b58ff419ebb1db3b453f128292
  • alt-python312-tkinter-3.12.14-3.el10.x86_64.rpm
    sha:0b2361218abf729078d021df274296b8da1083f970edda60d179906882b47688
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.