[CLSA-2025:1759510395] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:53:19 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:87f7d8884d6f9cc72606a82a966f696da5b5b680
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:be21f05ddc7b66314922a1dafe5d07ce1b820b0c
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:4392287e2be843203a44594e6bd9d4a912df7499
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:a2300297bc199f2a01e10be7ed6ec7158f345a3e
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:8690b29ddbb7c2d5fafbf2033b2e074209590f73
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:8180c54af9e996322d47087676e4cfbba1e0c3de
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:ec4a1d9c6d6d379b68478f36623bd7eef46b127d
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:6b89bb902f6e1d877d66c9bd2ccd4906bb4a62bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.