[CLSA-2025:1748330202] alt-python36: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2025-05-31 15:27:12 UTC
Description:
- CVE-2023-24329: make urllib.parse.urlparse enforce that a scheme must begin with an alphabetical ASCII character - CVE-2023-40217: check for & avoid the ssl pre-close flaw - CVE-2024-6232: remove backtracking when parsing tarfile headers - CVE-2024-7592: fix quadratic complexity in parsing double-quoted cookie values with backslashes
Updated packages:
  • alt-python36-3.6.15-6.el6.x86_64.rpm
    sha:2deb1b38b974d9efb7082c4fcc7e6be3fc37b883bac17d59fd708abca96957c0
  • alt-python36-debug-3.6.15-6.el6.x86_64.rpm
    sha:b3fb1e0f8801a90c7b752db70cebf022bfd21dcdf3cb29cdd3afce6247335c0c
  • alt-python36-devel-3.6.15-6.el6.x86_64.rpm
    sha:367718c330522a6ca145ce743f5c378aaf5fbc93e82c3b180b1a3945cffa76ca
  • alt-python36-libs-3.6.15-6.el6.x86_64.rpm
    sha:972d532800d4549ff12ef1c5cdd881fd131340ca4e6d4da023d81febe4b3dde5
  • alt-python36-test-3.6.15-6.el6.x86_64.rpm
    sha:0734fc077fc6c824f6507054884e5294f6d321816b9f31b77d6199ccbeba7595
  • alt-python36-tkinter-3.6.15-6.el6.x86_64.rpm
    sha:7df990af8294c0b50d54db03a1a0a168662c4e5bdc24593dd91a4b1d35024020
  • alt-python36-tools-3.6.15-6.el6.x86_64.rpm
    sha:1d83544bddebffa80c642c19d6bea80a4593f2d4e2a2379bb3e521920fc920f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.