[CLSA-2026:1788292705] alt-python312: Fix of CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-01 19:58:36 UTC
Description:
- CVE-2025-15367: reject control characters in poplib POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command
CVEs fixed:
Updated packages:
  • alt-python312-3.12.14-3.el7.x86_64.rpm
    sha:e34cf392b4344a78d1ec179c096d882d65f9003781e80cd809a2b8894862f9d6
  • alt-python312-debug-3.12.14-3.el7.x86_64.rpm
    sha:f59b879c46174d293734191d741619a7e8b80f291fefccb42a1c2582c309549f
  • alt-python312-devel-3.12.14-3.el7.x86_64.rpm
    sha:25fb1c68bc03849acfa25bf033fc1b0e6acacd9f7113fba3740262f943cec0f3
  • alt-python312-idle-3.12.14-3.el7.x86_64.rpm
    sha:f85cd55c2b1eeae525a1a51c6d4b71851231f0cd50f614725e07170914d839f3
  • alt-python312-libs-3.12.14-3.el7.x86_64.rpm
    sha:79954fa81f37ecf2df9137d57dc69be4698fd21bbc94b89c7a896f9333997a88
  • alt-python312-test-3.12.14-3.el7.x86_64.rpm
    sha:83122b9008434ace4d95989c2c2330b816d86db8d8783826b440f7da529712aa
  • alt-python312-tkinter-3.12.14-3.el7.x86_64.rpm
    sha:7f54c1f09746ef515ebf780861bde3d1844c88adbb402fcda72ac2358ce36faf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.