[CLSA-2025:1750780647] Fix CVE(s): CVE-2024-11168, CVE-2025-0938
Type:
security
Severity:
Moderate
Release date:
2025-06-24 15:57:33 UTC
Description:
* SECURITY UPDATE: Improper validation of bracketed hosts in urllib - debian/patches/CVE-2024-11168.patch: add checks to ensure that bracketed hosts found by urlsplit are of IPv6 or IPvFuture format - CVE-2024-11168 * SECURITY UPDATE:Incomplete validation of bracketed hosts in urllib - debian/patches/CVE-2025-0938.patch: disallow square brackets (`[` and `]`) in domain names for parsed URLs - CVE-2025-0938
Updated packages:
  • idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_all.deb
    sha:d2cce4c8fcf245d72c816d1fa7a75f51e0c15cc4
  • libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:d12726a54af41e800ece772fcfdf4161cb99aad4
  • libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:82cb9c87d1be48853efe19047e94f1ca2c55b89e
  • libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:8f194404260b23409a2ee0ef7a1d42f412e64e90
  • libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:a4f87fcba375f7abca39a40d48d818eba91d7bf5
  • libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_all.deb
    sha:f34a8584444242238ab8bf80dd3c2f16a79a7fd1
  • python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:0d9209316b618f9b71266cf8ca96821bf6ddf687
  • python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:960ee30157c160dd61a53ba1619f92977aae81c7
  • python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_all.deb
    sha:755e306ece7ba587095c75eb8f0c8e92d0eafcd7
  • python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_all.deb
    sha:1f4e74378ea4d1c36f13a948cbd2ac47e6017b75
  • python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:d1a37281e4543c1de46f92e5dbd48e318ea17227
  • python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els14_amd64.deb
    sha:7cd5eb3c8bd6262824abcfe9773f06815019d6d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.