Release date:
2026-09-01 13:54:21 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib
- debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch:
reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a
user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93).
- CVE-2025-15367
Updated packages:
-
alt-python312_3.12.14-4_amd64.deb
sha:23b45b0848a040da1aa5fa26c08c152fd71c70ec
-
alt-python312-debug_3.12.14-4_amd64.deb
sha:270c3f01aae60741e324566346a69b5319fb6305
-
alt-python312-devel_3.12.14-4_amd64.deb
sha:d54c05df8f12c1f8f20d11fdac67fd1fa6fcef58
-
alt-python312-idle_3.12.14-4_amd64.deb
sha:16934daa6be6d634f8efb3abfd7be418ee4afdab
-
alt-python312-libs_3.12.14-4_amd64.deb
sha:a971437c1445c5bbf4e03a9c927ca84b35c5e85e
-
alt-python312-test_3.12.14-4_amd64.deb
sha:a0e394b8341a2b0288e4ccd04a336c65bad664dd
-
alt-python312-tkinter_3.12.14-4_amd64.deb
sha:b93e1331c72af441abf04261eef1fece2965fc9f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.