[CLSA-2025:1760093799] Fix of 8 CVEs
Type:
security
Severity:
Critical
Release date:
2025-10-10 10:56:43 UTC
Description:
* SECURITY UPDATE: DoS in case of malicious XML entity declarations - debian/patches/CVE-2022-48565.patch: reject XML entity declarations in plist files - CVE-2022-48565 * SECURITY UPDATE: Bypassing blocklisting methods by supplying a URL that starts with blank characters - debian/patches/CVE-2023-24329.patch, debian/patches/CVE-2023-24329-2.patch: prevent urllib.parse.urlparse from accepting schemes that don't begin with an alphabetical ASCII character - CVE-2023-24329 * SECURITY UPDATE: ReDoS via specifically-crafted tar archives - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing tarfile - CVE-2024-6232 * SECURITY UPDATE: Excessive CPU usage while parsing a cookie value - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in parsing double-quoted cookie values with backslashes - CVE-2024-7592 * SECURITY UPDATE: CPU DoS by crafting inputs to the IDNA decoder - debian/patches/CVE-2022-45061.patch: fix quadratic time idna decoding - CVE-2022-45061 * SECURITY UPDATE: Use-after-free via heappushpop in heapq - debian/patches/CVE-2022-48560.patch: fix posible crash in heapq with custom comparison operators - debian/patches/CVE-2022-48560-2.patch: add tests for CVE-2022-48560 - CVE-2022-48560 * SECURITY UPDATE: DoS by HTTP client infinite line reading from malicious server after a 100 Continue response - debian/patches/CVE-2021-3737.patch: stop reading a header if it's too long - CVE-2021-3737 * SECURITY UPDATE: A flaw in the urllib.parse module - debian/patches/CVE-2022-0391.patch: make urlparse sanitize URLs containing ASCII newline and tabs - CVE-2022-0391
Updated packages:
  • alt-python27_2.7.18-6_amd64.deb
    sha:4c77bfa1e5c161ca33b6e83a09919b1cd53810af
  • alt-python27-debug_2.7.18-6_amd64.deb
    sha:4abf8c6b43d0eb62835e698d47fb2f59b4e7640e
  • alt-python27-devel_2.7.18-6_amd64.deb
    sha:fd0da3896b884fef2d780819bdbee0010075082f
  • alt-python27-idle_2.7.18-6_amd64.deb
    sha:fb8a9040fb11bac092054906f999d6e043f013a6
  • alt-python27-libs_2.7.18-6_amd64.deb
    sha:993eeea38e2345be1b23fefcf6184af85b250ce9
  • alt-python27-test_2.7.18-6_amd64.deb
    sha:8d5337b4140ff0cfcca37d4dc28b2a15f6307684
  • alt-python27-tkinter_2.7.18-6_amd64.deb
    sha:915c10faddb89a0ccc9633c19d54e2b8a2ff9094
  • alt-python27-tools_2.7.18-6_amd64.deb
    sha:308b1d20ff1d14d50fb66fc09dd74bae4a6c3c31
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.