[CLSA-2026:1781100487] Fix CVE(s): CVE-2025-15366, CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-06-10 14:08:28 UTC
Description:
* SECURITY UPDATE: command injection via control characters in imaplib - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of cpython 6262704b (gh-143921, Seth Michael Larson). imaplib.IMAP4._command() concatenated each argument into the wire-level command without inspecting it, so user-controlled text (e.g. a username passed to IMAP4.login()) containing CR/LF or other control characters could inject a second IMAP command. Adds a module-level _control_chars regex to Lib/imaplib.py and a guard in _command() that rejects any argument containing a byte in [\x00-\x1F\x7F] with ValueError before concatenation. Adds a test_control_characters regression test to Lib/test/test_imaplib.py. - CVE-2025-15366 * SECURITY UPDATE: command injection via control characters in poplib - debian/patches/CVE-2025-15366-CVE-2025-15367.patch: backport of cpython b234a2b6 (gh-143923, Seth Michael Larson). poplib.POP3._putcmd() sent its argument to the server without inspecting it, so user-controlled text passed to user()/pass_()/apop()/rpop()/top() could inject a second POP3 command. Adds a guard in _putcmd() (Lib/poplib.py) that rejects any argument containing a byte in [\x00-\x1F\x7F] with ValueError before sending. Adds a test_control_characters regression test to Lib/test/test_poplib.py. - CVE-2025-15367
Updated packages:
  • alt-python27_2.7.18-21_amd64.deb
    sha:557fa60f0066d1193b5dafe428e65b445956d5ee
  • alt-python27-debug_2.7.18-21_amd64.deb
    sha:d69350e8df7be8cb71e3c46356caad8b802fd891
  • alt-python27-devel_2.7.18-21_amd64.deb
    sha:65d0c91b833cb47b49ac341f52aad405a9108986
  • alt-python27-idle_2.7.18-21_amd64.deb
    sha:71544a78edc3be464d58a001bcafad02ec970ac1
  • alt-python27-libs_2.7.18-21_amd64.deb
    sha:ae5a65554e5fa7ceffdbd6319cee91e9766478d3
  • alt-python27-test_2.7.18-21_amd64.deb
    sha:7b7e5bb1d0c69a06f543b1dba14f750555ade582
  • alt-python27-tkinter_2.7.18-21_amd64.deb
    sha:b4463a4b60e3e18ccbb25d17025db5c7af97c6db
  • alt-python27-tools_2.7.18-21_amd64.deb
    sha:b4a40bb3d8f4be4aa161f70fd0e62f8d2f04892a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.