[CLSA-2026:1788280189] alt-python312: Fix of CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-01 16:29:59 UTC
Description:
- CVE-2025-15367: reject control characters in poplib POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-3.el8.x86_64.rpm
    sha:99251ebcc84d88f65228223e7b00cbc58bb9ab4bb514382c28afa0c8d0bd1bda
  • alt-python312-debug-3.12.14-3.el8.x86_64.rpm
    sha:8c6bd97bf38e69c5f32d47fcfd4b19909398813c03e3282cd1742900787c63de
  • alt-python312-devel-3.12.14-3.el8.x86_64.rpm
    sha:1f10dee50504238effada2cb5c990445fb19bb5fe385f4555c0e1bdb0705eddf
  • alt-python312-idle-3.12.14-3.el8.x86_64.rpm
    sha:7c73f7690f48bfe547896a470f9b483c7d08a338a6f594b0c69a7a0866028812
  • alt-python312-libs-3.12.14-3.el8.x86_64.rpm
    sha:090b045193496f9fe94f539c1b948e151fdf38f500a241e33de862eb92c2ebdc
  • alt-python312-test-3.12.14-3.el8.x86_64.rpm
    sha:eb3d4512a98e5f34cdf27dd2c0cbe1f7c7e6c070e717cc4741e5dbbbe4370f99
  • alt-python312-tkinter-3.12.14-3.el8.x86_64.rpm
    sha:97ca469845250de16d812103222052979ec279a4a011107961ea4c4ffe321e41
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.