[CLSA-2024:1727895166] Fix CVE(s): CVE-2024-6232, CVE-2024-7592
Type:
security
Severity:
Important
Release date:
2024-10-02 18:52:49 UTC
Description:
* SECURITY UPDATE: Regular expressions that allowed excessive backtracking during tarfile - debian/patches/CVE-2024-6232.patch: fix regexp handling in tarfile - CVE-2024-6232 * SECURITY UPDATE: Algorithm with quadratic complexity using excess CPU resources while parsing the cookie value - debian/patches/CVE-2024-7592.patch: fix algorithm with quadratic complexity - CVE-2024-7592
Updated packages:
  • idle-python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_all.deb
    sha:ca4b56d06384e99d6d791d22374e450c91ed27fa
  • libpython2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:4c2cc241c296d49efc1230d2ce70346d1b3f0884
  • libpython2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:f08cb611757ac9c97e5c47ce4f86a97c8152b717
  • libpython2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:cb13ec973a38e1df245eed053747d6d4f85aa81e
  • libpython2.7-stdlib_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:e52ad374942fc73a171f3cbea0a054d25ba75962
  • libpython2.7-testsuite_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_all.deb
    sha:c7e61e76894d901467df61924ee15fc5adc25f29
  • python2.7_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:6baab4355f4438792200501d57710f7b470cd370
  • python2.7-dev_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:4733604166ae4ebd1219e3a3ff887c8f67d393e0
  • python2.7-doc_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_all.deb
    sha:0771deeb016f3558f96ebcf9d5ce24a8f4e7b19f
  • python2.7-examples_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_all.deb
    sha:c47c86cdbe396bbafb92e5650a45907b4a93063b
  • python2.7-minimal_2.7.12-1ubuntu0~16.04.18+tuxcare.els14_amd64.deb
    sha:71d3baf8d6850920f90b4e8be93ac65b551ebbd3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.