[CLSA-2026:1788270623] alt-python312: Fix of CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-01 13:50:32 UTC
Description:
- CVE-2025-15367: reject control characters in poplib POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-3.el9.x86_64.rpm
    sha:f41bba5920dab156e8a15a12bb18666dad319ed0d481ba8e3f12e9f62965e782
  • alt-python312-debug-3.12.14-3.el9.x86_64.rpm
    sha:afaac3a96c63ca59b4dcf3f377f2357bf73bd3f68c5b6c3c571805ba3a96b28a
  • alt-python312-devel-3.12.14-3.el9.x86_64.rpm
    sha:55d72d223c8bdd8b76980196185c9249fdc030853e4c855a2d15168547ebce3e
  • alt-python312-idle-3.12.14-3.el9.x86_64.rpm
    sha:1dfb501eeefa54154faa534cbc049a303629a1d4721ca9cfb79308f44d1a1205
  • alt-python312-libs-3.12.14-3.el9.x86_64.rpm
    sha:ecee5d97c8b1dffd0779444661148964f532fef8f75845d5437e9a5b3b6a1c68
  • alt-python312-test-3.12.14-3.el9.x86_64.rpm
    sha:8b7a56e89fdabbd5dc10751fc6843a3873c2c228594e7682f166e068b626b1f4
  • alt-python312-tkinter-3.12.14-3.el9.x86_64.rpm
    sha:6f32d5c974b4bccd68da410fe5337b80ff66cbc57fc2183ef67c380dd805eeb0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.