[CLSA-2026:1788344446] alt-python313: Fix of CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-02 10:20:58 UTC
Description:
- CVE-2025-15367: reject control characters in poplib POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command
CVEs fixed:
Updated packages:
  • alt-python313-3.13.15-2.el10.x86_64.rpm
    sha:cdd9485759b124b8cc01de266522ad23a57db59f4b241caabba5ef50990a7824
  • alt-python313-debug-3.13.15-2.el10.x86_64.rpm
    sha:e730fa44cf1e07a8b2d390db84c626d88e7733b1930c581dec4e413be09cb873
  • alt-python313-devel-3.13.15-2.el10.x86_64.rpm
    sha:227f9924dd927b4f10831bb3104bb5547700db58cb7fa9b4bbb8a7a6bf99fb3b
  • alt-python313-idle-3.13.15-2.el10.x86_64.rpm
    sha:cc9f5c5c1b2ffbad8699b9251240891087fda43657b7646443ad1b1cfdbd7b78
  • alt-python313-libs-3.13.15-2.el10.x86_64.rpm
    sha:38a9f75f5be674773bb765b9f89d898b681105f9b65955234828853b3dbd4933
  • alt-python313-test-3.13.15-2.el10.x86_64.rpm
    sha:c38cd18f12756ffd9be4a77ef301c595bd0f1fad4c24945638132c9394d03d09
  • alt-python313-tkinter-3.13.15-2.el10.x86_64.rpm
    sha:c18d1baa617a8cc28763bcf85221bfe5a86cc5fda0c7541ccc31197db06bf6bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.