Publishing details

Changelog

python3.12 (3.12.0-1ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: improper privilege management
    - debian/patches/CVE-2023-6507.patch: Restore `subprocess`'s intended
      use of `vfork()` by default.
    - CVE-2023-6507
  * SECURITY UPDATE: incorrect permission assignment
    - debian/patches/CVE-2023-6597.patch: fix symlink bug in cleanup.
    - CVE-2023-6597
  * SECURITY UPDATE: Zip-Bombs with overlap entries
    - debian/patches/CVE-2024-0450.patch: Protect zipfile from
      "quoted-overlap" zipbomb. Raise BadZipFile when try to read an
      entry that overlaps with other entry or central directory.
    - CVE-2024-0450

 -- Allen Huang <email address hidden>  Sun, 28 Apr 2024 23:42:26 +0100

Available diffs

Builds

Built packages

Package files