[CLSA-2024:1724259346] Fix CVE(s): CVE-2024-0450
Type:
security
Severity:
Moderate
Release date:
2024-08-21 16:55:49 UTC
Description:
* SECURITY UPDATE: Prevent Quoted-Overlap Zip-Bombs - debian/patches/CVE-2024-0450.patch: Protect zipfile from quoted-overlap zipbomb by raising BadZipFile when trying to read an entry that overlaps with other entry or central directory - CVE-2024-0450
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb
    sha:2a2c979d35c330e8fd260c50abdb8e64f68860a5
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:6a2d2a047fd1aab4c905deb1121ded63b9190c59
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:a3f1f23163070de4daf34928ada847f388be28ec
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:913a7139a6c10d9958c1aed82dc9031199236aeb
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:cb963cf2c7360d6efcc49d2237e85503e35e1542
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb
    sha:6e7f9846216ff108f21a4b9d1cc777a8241e7f78
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:586ed40e3942da1f295cc539cd71ff541b5c1bd0
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:a6a7d243f7f61387a6f226487848242edfe5179f
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb
    sha:822647ce390d9eae34cbbf60e32c90e7deac1fcc
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb
    sha:e19ff595bef87d2ba3ccc33100234344cd897b02
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:5c493f6c1b90ac2ac1cbc211dfa02f26581a254a
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb
    sha:a60cf82ab7aa2ad949a88aede3396b30feb7c005
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.