[CLSA-2024:1728071619] python: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2024-10-04 19:53:42 UTC
Description:
- CVE-2024-7592: fix algorithm with quadratic complexity to avoid using excess CPU resources while parsing the cookie value - CVE-2024-6232: fix regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing and was vulnerable to ReDoS via specifically-crafted tar archives
Updated packages:
  • python-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:8b5299b752231126b385db8fbc7537aa231623f10011c9d16937b15f217ae743
  • python-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:4c30ec845925864a338f0a1304f0c0d236c2d395a40bef647d76444e880300fc
  • python-devel-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:afa6ef783535921c137ac9ff263996370561149768feae46d913e15348ec8383
  • python-devel-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:940ed0c6f2d6e85c7f37d4e968838060e0c72b17d8fa330073e81c8542f0fcbe
  • python-libs-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:6bb39707edc4009aa3259fb178928d872fccdb9a56c318e48ddd1eee4f894384
  • python-libs-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:bd4b0d2e717d50804feceaeb71011d2c89014ad29669ebd093fc59a8c47bc4ca
  • python-test-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:4b4f6aa95e8d2573d70256e505489ea7e36c84e358f2fe0dcdabbf903035cb29
  • python-tools-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:add52acfa2bf2c935049823a004862ecce27e97f01b4b77071f8d2d73434f6a2
  • tkinter-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:0c94ebdbebb60e7ad73aeb7a881eb4e63cfcea71eb9b99c425941f05b2ded380
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.