[CLSA-2024:1720178532] python3: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2024-07-05 11:22:15 UTC
Description:
- CVE-2023-6597: Prevent tempfile.TemporaryDirectory class dereference symlinks - CVE-2024-0450: Make zipfile module reject zip archives which overlap entries in the archive. Prevent “quoted-overlap” zip-bombs exploit.
Updated packages:
  • platform-python-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:7f6404837619b093a1ee84a482e0d080456a8e3b
  • platform-python-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:0255933e2c9f93b1313d7a626416f8c8cbd6ff9f
  • platform-python-debug-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:952089ef803039b4a8de71123cd115be7c5cf888
  • platform-python-debug-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:b3d8ad8b70fd893aafa895f0758a72b0ec82040f
  • platform-python-devel-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:7ebe6ad79498ddcc35b7a7725b9222e6ff1db21d
  • platform-python-devel-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:1b5aa6dc511452a69bec4b6f33d6cf069d7daae9
  • python3-devel-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:2485b8fbd2690775be545416ac30a1f50acd1d6c
  • python3-idle-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:98bc0e80a69f113d67cc64d3dd95ce5e61251aad
  • python3-idle-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:e1a372823c45e4ef7b9d1ebe2fcf55ee851e49f2
  • python3-libs-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:f50d07ec4ab4c6bb332c3c45ac478098746d0e40
  • python3-libs-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:923ba15f66a4dfabea6823c75aa9469f25cbebd1
  • python3-test-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:27b82cbb98ec1a10e7721b1f49097afd37439a17
  • python3-test-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:cefa3089534f66be1016fc1c6cdfe9154244b777
  • python3-tkinter-3.6.8-40.el8_4.tuxcare.els6.i686.rpm
    sha:7dacd9016d503ea51fb488eaa55ca44db1a74747
  • python3-tkinter-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm
    sha:9b657f81a72bb1795b8bbae299bb2610386b4023
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.