Release Info

Advisory: CLSA-2024:1720178532

OS: CentOS 8.4 ELS

Public date: 2024-07-05 07:22:14

Project: python3

Version: 3.6.8-40.el8_4.tuxcare.els6

Errata link: https://errata.tuxcare.com/els_os/centos8.4els/CLSA-2024-1720178532.html

Changelog

- CVE-2023-6597: Prevent tempfile.TemporaryDirectory class dereference symlinks - CVE-2024-0450: Make zipfile module reject zip archives which overlap entries in the archive. Prevent “quoted-overlap” zip-bombs exploit.

Update

Update command: dnf update python3*

Packages list

platform-python-3.6.8-40.el8_4.tuxcare.els6.i686.rpm platform-python-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm platform-python-debug-3.6.8-40.el8_4.tuxcare.els6.i686.rpm platform-python-debug-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm platform-python-devel-3.6.8-40.el8_4.tuxcare.els6.i686.rpm platform-python-devel-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm python3-devel-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm python3-idle-3.6.8-40.el8_4.tuxcare.els6.i686.rpm python3-idle-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm python3-libs-3.6.8-40.el8_4.tuxcare.els6.i686.rpm python3-libs-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm python3-test-3.6.8-40.el8_4.tuxcare.els6.i686.rpm python3-test-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm python3-tkinter-3.6.8-40.el8_4.tuxcare.els6.i686.rpm python3-tkinter-3.6.8-40.el8_4.tuxcare.els6.x86_64.rpm

CVEs

CVE-2024-0450
CVE-2023-6597