[CLSA-2024:1728071284] python: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2024-10-04 19:48:08 UTC
Description:
- CVE-2024-7592: fix algorithm with quadratic complexity to avoid using excess CPU resources while parsing the cookie value - CVE-2024-6232: fix regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing and was vulnerable to ReDoS via specifically-crafted tar archives
Updated packages:
  • python-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:5018f7f5f83ae218eb941056df0193697e02c82ffe443f3f28c41abb9399c500
  • python-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:152ebb5422880fd8c51a3bd539fc38d3b030ea1c693dd5a6660fd640969f7006
  • python-devel-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:cf33a84a71c48137f266b43f1a722d0d5d1bec7bce62ed78afea66b47573b416
  • python-devel-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:183edae82bb563386df686ee98fa44a18faf84b717bb526e70d47fb1a2caa4fe
  • python-libs-2.6.6-70.el6.tuxcare.els14.i686.rpm
    sha:48a87e2205fcda40aa3cad72add38709d91adcc9c1e9ae874e54b5415615c0c0
  • python-libs-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:e75efcd9bc8e7cbf70ad50ca78ffb0f7f0b6a2437f5a77b8ff14aeb895a9a32f
  • python-test-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:ec2216d8af31f66b457e57df807fd4643bb83332c054a0e4134d4cb42a8e90c6
  • python-tools-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:badadc4155879d8acd84ea735eb887d7b5926dac7bdc28ce22f48f528fd8d454
  • tkinter-2.6.6-70.el6.tuxcare.els14.x86_64.rpm
    sha:ca5b164ab9fc623e1d7c324de026fc4eb2c2a30e5cdc8b35744ba7dddab7e6bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.