[CLSA-2025:1759510328] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:52:13 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:f0f124b056fb93770e98ecc1314581ec83a35b77
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:001e329253e9448a0e5506a4c39d0e3f44ad115e
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:0f07313d395caebdaf3cc660828a9026759c091e
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:b286ca7e2ad6b97052fa4e23230c3dd7f78af4ef
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:74f5a8158303af6434257078e2f7449203f20fe2
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:53096e8ff6503a47dfb82988fbdcaf1ef81c8939
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:7d75bb599800888eea6860abd525aa52902b9b0c
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:638685a23352cfbb0130ca36da35a1f8d56483c1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.