Adrian Bunk
2024-12-04 21:40:02 UTC
Package: release.debian.org
Severity: normal
Tags: bookworm moreinfo
User: ***@packages.debian.org
Usertags: pu
X-Debbugs-Cc: ***@debian.org, Matthias Klose <***@debian.org>
* CVE-2023-27043: Reject malformed addresses in email.parseaddr()
(Closes: #1059298)
* CVE-2024-6923: Encode newlines in headers in the email module
* CVE-2024-7592: Quadratic complexity parsing cookies with backslashes
* CVE-2024-9287: venv activation scripts did't quote paths
* CVE-2024-11168: urllib functions improperly validated bracketed hosts
Tagged moreinfo, as question to the security team whether they want
this in -pu or as DSA.
Severity: normal
Tags: bookworm moreinfo
User: ***@packages.debian.org
Usertags: pu
X-Debbugs-Cc: ***@debian.org, Matthias Klose <***@debian.org>
* CVE-2023-27043: Reject malformed addresses in email.parseaddr()
(Closes: #1059298)
* CVE-2024-6923: Encode newlines in headers in the email module
* CVE-2024-7592: Quadratic complexity parsing cookies with backslashes
* CVE-2024-9287: venv activation scripts did't quote paths
* CVE-2024-11168: urllib functions improperly validated bracketed hosts
Tagged moreinfo, as question to the security team whether they want
this in -pu or as DSA.