Release date:
2025-11-07 14:43:39 UTC
Description:
* SECURITY UPDATE: Traversing outside chmod directory
- debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
-2025-4435-CVE-2025-4517.patch: re-filters directory members
before chmod/chown
- CVE-2024-12718
* SECURITY UPDATE: Symlink exfiltration
- debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
-2025-4435-CVE-2025-4517.patch: properly handles different link
semantics
- CVE-2025-4138
* SECURITY UPDATE: Hardlink Fallback Attack
- debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
-2025-4435-CVE-2025-4517.patch: re-filter the source if hardlink
extraction falls back to copying
- CVE-2025-4330
* SECURITY UPDATE: Errorlevel=0 Extracts Rejected Members
- debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
-2025-4435-CVE-2025-4517.patch: account errorlevel
- CVE-2025-4435
* SECURITY UPDATE: PATH_MAX Attack
- debian/patches/CVE-2024-12718-CVE-2025-4138-CVE-2025-4330-CVE
-2025-4435-CVE-2025-4517.patch: prevents PATH_MAX overflow
attacks
- CVE-2025-4517
* TEST UPDATE: Incorrect encoding leading to an unexpected
exception in test_tarfile.py
- debian/patch/fix_test_tarfile-enconding.patch: fix encoding
Updated packages:
-
alt-python36_3.6.15-19_amd64.deb
sha:a6c46b0774de065aadc5881f2ac9ac9b7a306874
-
alt-python36-debug_3.6.15-19_amd64.deb
sha:cde726515f218ceba3d3aeca6a9598f78ccfa103
-
alt-python36-devel_3.6.15-19_amd64.deb
sha:420be5f3d1ce48c5dcd2e922585c9fdfdd2d7d8a
-
alt-python36-libs_3.6.15-19_amd64.deb
sha:2c98f762a9cbd46df590b0101902b3c2510e6ccb
-
alt-python36-test_3.6.15-19_amd64.deb
sha:4f994416efc8a52ed0e4d0c4ca18b29d8cc7858f
-
alt-python36-tkinter_3.6.15-19_amd64.deb
sha:f130eeaa28b13b897a8b1e66a609089fb35467c8
-
alt-python36-tools_3.6.15-19_amd64.deb
sha:117a38bd0d765e52a01618c21c146a8e1b842035
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.