[CLSA-2025:1748350001] alt-python36: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2025-05-31 15:25:39 UTC
Description:
- CVE-2023-24329: make urllib.parse.urlparse enforce that a scheme must begin with an alphabetical ASCII character - CVE-2023-40217: check for & avoid the ssl pre-close flaw - CVE-2024-6232: remove backtracking when parsing tarfile headers - CVE-2024-7592: fix quadratic complexity in parsing double-quoted cookie values with backslashes
Updated packages:
  • alt-python36-3.6.15-6.el7.x86_64.rpm
    sha:a3d7293cbe2268a6d030dc17ebd39ebdb2f1dd65b2c472095d0ae2d125167033
  • alt-python36-debug-3.6.15-6.el7.x86_64.rpm
    sha:9941ffed7ea4bdcac2df2210d8a68423d4506cf357b52494196479d1686ac430
  • alt-python36-devel-3.6.15-6.el7.x86_64.rpm
    sha:70e2f25cba52907f4bfdeba19795490535f78601302082a4f8f3eabaf9376455
  • alt-python36-libs-3.6.15-6.el7.x86_64.rpm
    sha:d694c73289f1cb5805496de9f9e3240c2e7419a66309c1b865f524886dd94e52
  • alt-python36-test-3.6.15-6.el7.x86_64.rpm
    sha:919d5c9b02d997d61d99e0a7f82f7af5c315539255e0473f4a6b094a7d440b88
  • alt-python36-tkinter-3.6.15-6.el7.x86_64.rpm
    sha:88a97dcf518577f5b21ddcf729b4a1ee3b3668f65294414458bd918e7117ff50
  • alt-python36-tools-3.6.15-6.el7.x86_64.rpm
    sha:2dfb7550bfbb80d5a777592de16946d69b4494d02353c327171ccef12960d10f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.