Release Info

Advisory: CLSA-2024:1724259346

OS: Ubuntu 18.04 ELS

Public date: 2024-08-21 12:55:48

Project: python3.6

Version: 3.6.9-1~18.04ubuntu1.12+tuxcare.els7

Errata link: https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2024-1724259346.html

Changelog

* SECURITY UPDATE: Prevent Quoted-Overlap Zip-Bombs - debian/patches/CVE-2024-0450.patch: Protect zipfile from quoted-overlap zipbomb by raising BadZipFile when trying to read an entry that overlaps with other entry or central directory - CVE-2024-0450

Update

Update command: apt-get update apt-get --only-upgrade install python3.6*

Packages list

idle-python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb libpython3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb libpython3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb libpython3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb libpython3.6-stdlib_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb libpython3.6-testsuite_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb python3.6_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb python3.6-dev_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb python3.6-doc_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb python3.6-examples_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_all.deb python3.6-minimal_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb python3.6-venv_3.6.9-1~18.04ubuntu1.12+tuxcare.els7_amd64.deb

CVEs

CVE-2024-0450