[CLSA-2025:1742466441] Fix CVE(s): CVE-2024-9287
Type:
security
Severity:
Important
Release date:
2025-03-20 10:27:26 UTC
Description:
* SECURITY UPDATE: Incorrect path quoting in venv allows command injection - debian/patches/CVE-2024-9287.patch: Quote template strings in venv activation - CVE-2024-9287
Updated packages:
  • idle-python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_all.deb
    sha:45bcaed918f0344fc53a4abd31a7b8ac900ef9a2
  • libpython3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:6833a008e12fe7c575bd763945f4876ab467f041
  • libpython3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:cba554c663872979018528753bea55142f3569da
  • libpython3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:98b600a17098f750c721d8ac3405c27a63332914
  • libpython3.5-stdlib_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:33627bcc620b42a0668ea46df656e084d6fc0811
  • libpython3.5-testsuite_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_all.deb
    sha:2c1ad06b6ffcd350069202f868a0dbb5652837a8
  • python3.5_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:38d0ce00a83bbc0f1c06f1a30dec7b10dcc52a73
  • python3.5-dev_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:b557661d0650773686fd208ae153e58480fe8290
  • python3.5-doc_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_all.deb
    sha:a36ac53f8d725fb5bf37fe2c25163c22a9d6fba2
  • python3.5-examples_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_all.deb
    sha:c5f5899b450dfeb8066b6a8b0001fd2a6ec87491
  • python3.5-minimal_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:43537ea05afbb573d90463f6041c986a4d468284
  • python3.5-venv_3.5.2-2ubuntu0~16.04.13+tuxcare.els18_amd64.deb
    sha:9b942b391013ea760b1bd6e5d7dd41b23157710d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.