Release date:
                    
                    
                        2025-10-10 11:02:19 UTC
                    
                 
                
                    
                        Description:
                    
                       * SECURITY UPDATE: DoS in case of malicious XML entity declarations
     - debian/patches/CVE-2022-48565.patch: reject XML entity declarations
       in plist files
     - CVE-2022-48565
   * SECURITY UPDATE: Bypassing blocklisting methods by supplying a URL
     that starts with blank characters
     - debian/patches/CVE-2023-24329.patch,
       debian/patches/CVE-2023-24329-2.patch: prevent urllib.parse.urlparse
       from accepting schemes that don't begin with an alphabetical ASCII
       character
     - CVE-2023-24329
   * SECURITY UPDATE: ReDoS via specifically-crafted tar archives
     - debian/patches/CVE-2024-6232.patch: remove backtracking when parsing
       tarfile
     - CVE-2024-6232
   * SECURITY UPDATE: Excessive CPU usage while parsing a cookie value
     - debian/patches/CVE-2024-7592.patch: fix quadratic complexity in
       parsing double-quoted cookie values with backslashes
     - CVE-2024-7592
   * SECURITY UPDATE: CPU DoS by crafting inputs to the IDNA decoder
     - debian/patches/CVE-2022-45061.patch: fix quadratic time idna
       decoding
     - CVE-2022-45061
   * SECURITY UPDATE: Use-after-free via heappushpop in heapq
     - debian/patches/CVE-2022-48560.patch: fix posible crash in heapq with
       custom comparison operators
     - debian/patches/CVE-2022-48560-2.patch: add tests for CVE-2022-48560
     - CVE-2022-48560
   * SECURITY UPDATE: DoS by HTTP client infinite line reading from
     malicious server after a 100 Continue response
     - debian/patches/CVE-2021-3737.patch: stop reading a header if it's
       too long
     - CVE-2021-3737
   * SECURITY UPDATE: A flaw in the urllib.parse module
     - debian/patches/CVE-2022-0391.patch: make urlparse sanitize URLs
       containing ASCII newline and tabs
     - CVE-2022-0391
                 
                
                    
                        Updated packages:
                    
                    
                        
                            - 
                                alt-python27_2.7.18-6_amd64.deb
                                
                                    sha:65f749115a40a7b29588f1eaa3e2dcce9d413725
                                
                             
                            - 
                                alt-python27-debug_2.7.18-6_amd64.deb
                                
                                    sha:568dd4b316eebe2e43681b9b4a9cf0dc6cf2daad
                                
                             
                            - 
                                alt-python27-devel_2.7.18-6_amd64.deb
                                
                                    sha:ed9a12edfc59039fae44e137f10f5c65bed8efa1
                                
                             
                            - 
                                alt-python27-idle_2.7.18-6_amd64.deb
                                
                                    sha:2ab8d1d3a0dac48f4f8a906bcd90b92fd9d216ac
                                
                             
                            - 
                                alt-python27-libs_2.7.18-6_amd64.deb
                                
                                    sha:b010b0de951bb0d7cece11839dc3e1b591343e14
                                
                             
                            - 
                                alt-python27-test_2.7.18-6_amd64.deb
                                
                                    sha:277df09caad5d7f3d918bd045c24bbbd19d1e9ea
                                
                             
                            - 
                                alt-python27-tkinter_2.7.18-6_amd64.deb
                                
                                    sha:b3795289023b2a4498534d1b06eb1f884bcfb576
                                
                             
                            - 
                                alt-python27-tools_2.7.18-6_amd64.deb
                                
                                    sha:169b65308ad470e8bf6ae81e74d0edd718512790
                                
                             
                        
                     
                 
                
                    
                        Notes:
                    
                    
                        This page is generated automatically and has not been checked for errors. For clarification or
                        corrections please contact the 
CloudLinux Packaging Team.