Release Info

Advisory: CLSA-2025:1767089726

OS: Debian 12

Public date: 2025-12-30 10:15:27.948359

Project: python

Version: 3.7.17-7

Errata link: https://errata.tuxcare.com/els_alt_python/debian12/CLSA-2025-1767089726.html

Changelog

* SECURITY UPDATE: Bypass of domain e-mail-based protection mechanism by incorrect parsing of e-mail addresses that contain a special character - debian/patches/CVE-2023-27043.patch: reject malformed addresses in email.parseaddr() - CVE-2023-27043 * SECURITY UPDATE: Bypass of the TLS handshake and included protections - debian/patches/CVE-2023-40217.patch: check for & avoid the ssl pre-close flaw - CVE-2023-40217

Update

Update command: apt-get update apt-get --only-upgrade install alt-python*

Packages list

alt-python37_3.7.17-7_amd64.deb alt-python37-debug_3.7.17-7_amd64.deb alt-python37-devel_3.7.17-7_amd64.deb alt-python37-libs_3.7.17-7_amd64.deb alt-python37-test_3.7.17-7_amd64.deb alt-python37-tkinter_3.7.17-7_amd64.deb alt-python37-tools_3.7.17-7_amd64.deb

CVEs

CVE-2023-27043
CVE-2023-40217