[CLSA-2026:1788444463] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-09-03 14:07:54 UTC
Description:
* SECURITY UPDATE: control-character command injection in imaplib - debian/patches/CVE-2025-15366.patch: reject control characters in IMAP4._command() so user-controlled arguments cannot inject extra IMAP commands or extra command arguments (CWE-77/CWE-93). - CVE-2025-15366
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-5_amd64.deb
    sha:46a6731608b6d2041127a5604344bb95720c86c8
  • alt-python312-debug_3.12.14-5_amd64.deb
    sha:2d8ff4acf34dedba3575c84ed313a2ee25a72002
  • alt-python312-devel_3.12.14-5_amd64.deb
    sha:9a7d6239379110a367878f4686f8b5b05cc2923f
  • alt-python312-idle_3.12.14-5_amd64.deb
    sha:a64bdab8ee7529b8138ce164dece0b39f27afd65
  • alt-python312-libs_3.12.14-5_amd64.deb
    sha:bf8d5e108a39d87ad6b37d4fb499913c3541ad5c
  • alt-python312-test_3.12.14-5_amd64.deb
    sha:8e77e30a073e71a77b269c269b20594948cb3ef5
  • alt-python312-tkinter_3.12.14-5_amd64.deb
    sha:dee6fd2f067f3372e9ef7c39bbbbdefa09a68809
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.