[CLSA-2026:1788428624] Fix CVE(s): CVE-2025-15366
Type:
security
Severity:
Important
Release date:
2026-09-03 09:43:55 UTC
Description:
* SECURITY UPDATE: control-character command injection in imaplib - debian/patches/CVE-2025-15366.patch: reject control characters in IMAP4._command() so user-controlled arguments cannot inject extra IMAP commands or extra command arguments (CWE-77/CWE-93). - CVE-2025-15366
CVEs fixed:
Updated packages:
  • alt-python312_3.12.14-5_amd64.deb
    sha:4d5fe9d6323cff037f5780721f2c0ca32628e0d9
  • alt-python312-debug_3.12.14-5_amd64.deb
    sha:2d8ff4acf34dedba3575c84ed313a2ee25a72002
  • alt-python312-devel_3.12.14-5_amd64.deb
    sha:69b3f6de599b3c1df23507c885ae5cafdea74395
  • alt-python312-idle_3.12.14-5_amd64.deb
    sha:91d24a4a19190fdd19b544cc8b7658416ceefbb7
  • alt-python312-libs_3.12.14-5_amd64.deb
    sha:641c3816e222f978db8cdae57a1bbf0f25660c48
  • alt-python312-test_3.12.14-5_amd64.deb
    sha:78847f97cf558d823f8e7dd6d9bacb335439bc0c
  • alt-python312-tkinter_3.12.14-5_amd64.deb
    sha:ee77338f56f48ab357515734e40be6564705e552
  • alt-python312_3.12.14-5_arm64.deb
    sha:553644128294d673e7aa39507b7b4d12f312808d
  • alt-python312-debug_3.12.14-5_arm64.deb
    sha:2def788604be5968a23ce122f02951d07bdb030f
  • alt-python312-devel_3.12.14-5_arm64.deb
    sha:c8e6bd9b25872552282fcfff2ccb569f620cb0e4
  • alt-python312-idle_3.12.14-5_arm64.deb
    sha:574a84ccedb144ab714c588b1100254dae8fce79
  • alt-python312-libs_3.12.14-5_arm64.deb
    sha:5d8512ce0acc33de738b4e72c46b5c3f9b94a96e
  • alt-python312-test_3.12.14-5_arm64.deb
    sha:3677b592f643ab08ef7b04de6c9dbc15e571f5c6
  • alt-python312-tkinter_3.12.14-5_arm64.deb
    sha:8a69454142234473a4cafa5919bc6a0e50ba3ee9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.