[CLSA-2025:1748352587] alt-python36: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2025-05-31 15:06:51 UTC
Description:
- CVE-2023-24329: make urllib.parse.urlparse enforce that a scheme must begin with an alphabetical ASCII character - CVE-2023-40217: check for & avoid the ssl pre-close flaw - CVE-2024-6232: remove backtracking when parsing tarfile headers - CVE-2024-7592: fix quadratic complexity in parsing double-quoted cookie values with backslashes
Updated packages:
  • alt-python36-3.6.15-6.el9.x86_64.rpm
    sha:6bb0315e9a6417ffe92a41978f590154c1e4a9aceababc3c42e4939040e0e86a
  • alt-python36-debug-3.6.15-6.el9.x86_64.rpm
    sha:c91a5cecab070872ab9fa08b6c3712885ffaff2f2268d8a2464411e057112bfb
  • alt-python36-devel-3.6.15-6.el9.x86_64.rpm
    sha:5ad8a31cea4b578f36919f2712f6072bf603f6fec8fc9ad8dca5834635527225
  • alt-python36-libs-3.6.15-6.el9.x86_64.rpm
    sha:bddaedbf5e4c57fc24ffc909ea7a82a4d8b426e7f7c27d9eebd187cef5d9c2b3
  • alt-python36-test-3.6.15-6.el9.x86_64.rpm
    sha:3e95733af03f7cb14d0ed94dba67a3d820044459180867ae2148e408a9df009d
  • alt-python36-tkinter-3.6.15-6.el9.x86_64.rpm
    sha:c0f35d03591a88f84ec44625308452f9069fdc6c7fa4af37bf0eb7197043911b
  • alt-python36-tools-3.6.15-6.el9.x86_64.rpm
    sha:3c993a07bb51f5588802fa89a9b2a94f0f4071141515f27a16644e80cfe99664
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.