[CLSA-2026:1788441451] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-09-03 13:17:44 UTC
Description:
* SECURITY UPDATE: control-character command injection in imaplib - debian/patches/CVE-2025-15366.patch: reject control characters in IMAP4._command() so user-controlled arguments cannot inject extra IMAP commands or extra command arguments (CWE-77/CWE-93). - CVE-2025-15366
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-5_amd64.deb
    sha:3cc77d432d1feea91b8d3d530c7b9504cd6ab184
  • alt-python312-debug_3.12.14-5_amd64.deb
    sha:2d8ff4acf34dedba3575c84ed313a2ee25a72002
  • alt-python312-devel_3.12.14-5_amd64.deb
    sha:998d0612c315061bbae7e08029342c308da08e30
  • alt-python312-idle_3.12.14-5_amd64.deb
    sha:a64bdab8ee7529b8138ce164dece0b39f27afd65
  • alt-python312-libs_3.12.14-5_amd64.deb
    sha:016db16588181274cf59b76e1fee58a1d18e8c05
  • alt-python312-test_3.12.14-5_amd64.deb
    sha:82a9249056002ad6840b7b4eca90842c7798579c
  • alt-python312-tkinter_3.12.14-5_amd64.deb
    sha:cb3a1f9664757391dc589bd311d6bfbf5c68a794
  • alt-python312_3.12.14-5_arm64.deb
    sha:5387bfe816b00cfd61147ab447b41156928ce156
  • alt-python312-debug_3.12.14-5_arm64.deb
    sha:2def788604be5968a23ce122f02951d07bdb030f
  • alt-python312-devel_3.12.14-5_arm64.deb
    sha:9fb519074ad7a3f2ddb319b575367815e4d77df9
  • alt-python312-idle_3.12.14-5_arm64.deb
    sha:70abfab44407ce82b29f2f56c3efdd3f34e29276
  • alt-python312-libs_3.12.14-5_arm64.deb
    sha:53872efd86262063ae9f5430f8bdab403764ffeb
  • alt-python312-test_3.12.14-5_arm64.deb
    sha:ab82250816817df1ecda15c78f358a71b87116f4
  • alt-python312-tkinter_3.12.14-5_arm64.deb
    sha:915b110399622f0e1236a31fbc258cebc5af8540
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.