[CLSA-2025:1748351993] alt-python36: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2025-05-31 15:22:41 UTC
Description:
- CVE-2023-24329: make urllib.parse.urlparse enforce that a scheme must begin with an alphabetical ASCII character - CVE-2023-40217: check for & avoid the ssl pre-close flaw - CVE-2024-6232: remove backtracking when parsing tarfile headers - CVE-2024-7592: fix quadratic complexity in parsing double-quoted cookie values with backslashes
Updated packages:
  • alt-python36-3.6.15-6.el8.x86_64.rpm
    sha:45514bfb43787df6aaf6647ad4fac4b5b0d77e255e25597552d2570dffcdb890
  • alt-python36-debug-3.6.15-6.el8.x86_64.rpm
    sha:3d724994fb69d4e70e0dfa6b780bc49b3d6811087d79c305bd1b3fe5c56cffc0
  • alt-python36-devel-3.6.15-6.el8.x86_64.rpm
    sha:ce1a9d2fa872b1f408b79f244c6e904c9ac0e83b51a2be412079a8b4d4afabb9
  • alt-python36-libs-3.6.15-6.el8.x86_64.rpm
    sha:c69817bebefdbeec14af3c81d968578b96e1a5cbc9bd6bc9ae9f1ebe25bc4155
  • alt-python36-test-3.6.15-6.el8.x86_64.rpm
    sha:6df1cfdb41d23acd73fe21bd0fda8aac226031596fd9f621830afd3af0ce16e6
  • alt-python36-tkinter-3.6.15-6.el8.x86_64.rpm
    sha:38e811c764910f6a7bb79ca3efbebabe6e35cdc86317455bed74229bd23ed0b2
  • alt-python36-tools-3.6.15-6.el8.x86_64.rpm
    sha:165abd461aea833fee073f1cbd5566108100274f1ec76ec88fecb54d48534718
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.