[CLSA-2026:1788438833] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-09-03 12:34:04 UTC
Description:
* SECURITY UPDATE: control-character command injection in imaplib - debian/patches/CVE-2025-15366.patch: reject control characters in IMAP4._command() so user-controlled arguments cannot inject extra IMAP commands or extra command arguments (CWE-77/CWE-93). - CVE-2025-15366
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-5_amd64.deb
    sha:c95c4eab8e54ed3989ad383e15395866e024dbee
  • alt-python312-debug_3.12.14-5_amd64.deb
    sha:2d8ff4acf34dedba3575c84ed313a2ee25a72002
  • alt-python312-devel_3.12.14-5_amd64.deb
    sha:4119aa157c7a7c3673bdb69ea531022eee03d200
  • alt-python312-idle_3.12.14-5_amd64.deb
    sha:09b15b481ee60a02391baed87b95c19e191bd63d
  • alt-python312-libs_3.12.14-5_amd64.deb
    sha:b5fd5802abf9aa1a984fa4ead87357a3ae4beff7
  • alt-python312-test_3.12.14-5_amd64.deb
    sha:e0bc3cea30c7230b3eee1bf603f292deeb500c44
  • alt-python312-tkinter_3.12.14-5_amd64.deb
    sha:b1f0a7f618c30c58025fa41400137a4e55177f88
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.