Release date:
2025-10-10 10:52:59 UTC
Description:
* SECURITY UPDATE: DoS in case of malicious XML entity declarations
- debian/patches/CVE-2022-48565.patch: reject XML entity declarations
in plist files
- CVE-2022-48565
* SECURITY UPDATE: Bypassing blocklisting methods by supplying a URL
that starts with blank characters
- debian/patches/CVE-2023-24329.patch,
debian/patches/CVE-2023-24329-2.patch: prevent urllib.parse.urlparse
from accepting schemes that don't begin with an alphabetical ASCII
character
- CVE-2023-24329
* SECURITY UPDATE: ReDoS via specifically-crafted tar archives
- debian/patches/CVE-2024-6232.patch: remove backtracking when parsing
tarfile
- CVE-2024-6232
* SECURITY UPDATE: Excessive CPU usage while parsing a cookie value
- debian/patches/CVE-2024-7592.patch: fix quadratic complexity in
parsing double-quoted cookie values with backslashes
- CVE-2024-7592
* SECURITY UPDATE: CPU DoS by crafting inputs to the IDNA decoder
- debian/patches/CVE-2022-45061.patch: fix quadratic time idna
decoding
- CVE-2022-45061
* SECURITY UPDATE: Use-after-free via heappushpop in heapq
- debian/patches/CVE-2022-48560.patch: fix posible crash in heapq with
custom comparison operators
- debian/patches/CVE-2022-48560-2.patch: add tests for CVE-2022-48560
- CVE-2022-48560
* SECURITY UPDATE: DoS by HTTP client infinite line reading from
malicious server after a 100 Continue response
- debian/patches/CVE-2021-3737.patch: stop reading a header if it's
too long
- CVE-2021-3737
* SECURITY UPDATE: A flaw in the urllib.parse module
- debian/patches/CVE-2022-0391.patch: make urlparse sanitize URLs
containing ASCII newline and tabs
- CVE-2022-0391
Updated packages:
-
alt-python27_2.7.18-6_amd64.deb
sha:caf12aff2ee4183d9c5e7cb1556b30abff4a8b5b
-
alt-python27-debug_2.7.18-6_amd64.deb
sha:05506e4e73111f1d20bfcf4497c897f34c715f24
-
alt-python27-devel_2.7.18-6_amd64.deb
sha:97fe0fcedca07898a5b4f870419bfadf60814edc
-
alt-python27-idle_2.7.18-6_amd64.deb
sha:a4fd93ad0efcab7a2fa40be92780bd721e94f632
-
alt-python27-libs_2.7.18-6_amd64.deb
sha:f8f4a81cd9b544c2b611ae62a79f5818caa0670f
-
alt-python27-test_2.7.18-6_amd64.deb
sha:dbc416753ac3570d9049c7a8c9a61453a7a9ea0e
-
alt-python27-tkinter_2.7.18-6_amd64.deb
sha:87fffa486386b1541638d27742fe5c62ea936e02
-
alt-python27-tools_2.7.18-6_amd64.deb
sha:aff55bfa1716a9013d965b9adccf1ba87437e798
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.