-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 02 May 2024 07:59:08 -0400 Source: python3.11 Binary: libpython3.11 libpython3.11-dbg libpython3.11-dev libpython3.11-minimal libpython3.11-stdlib python3.11 python3.11-dbg python3.11-dev python3.11-full python3.11-minimal python3.11-nopie python3.11-venv Architecture: amd64 Version: 3.11.2-6+deb12u2 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Stefano Rivera Description: libpython3.11 - Shared Python runtime library (version 3.11) libpython3.11-dbg - Debug Build of the Python Interpreter (version 3.11) libpython3.11-dev - Header files and a static library for Python (v3.11) libpython3.11-minimal - Minimal subset of the Python language (version 3.11) libpython3.11-stdlib - Interactive high-level object-oriented language (standard library python3.11 - Interactive high-level object-oriented language (version 3.11) python3.11-dbg - Debug Build of the Python Interpreter (version 3.11) python3.11-dev - Header files and a static library for Python (v3.11) python3.11-full - Python Interpreter with complete class library (version 3.11) python3.11-minimal - Minimal subset of the Python language (version 3.11) python3.11-nopie - Python interpreter linked without PIE (version 3.11) python3.11-venv - Interactive high-level object-oriented language (pyvenv binary, v Closes: 1070133 1070135 Changes: python3.11 (3.11.2-6+deb12u2) bookworm; urgency=medium . [ Steve McIntyre ] * Apply upstream security fix for CVE-2024-0450 Protect zipfile from "quoted-overlap" zipbomb. Closes: #1070133 * Apply and tweak upstream security fix for CVE-2023-6597 tempfile.TemporaryDirectory: fix symlink bug in cleanup Closes: #1070135 . [ Stefano Rivera ] * Apply upstream patch to avoid a potential null pointer dereference in fileutils. * Apply upstream security fix for CVE-2023-41105 os.path.normpath(): Path truncation at null bytes. * Apply upstream security fix for CVE-2023-40217 Avoid bypass TLS of handshake protections on closed sockets. * Apply upstream security fix for CVE-2023-24329 Strip C0 control and space characters in urlsplit. Checksums-Sha1: 1035012c8ff220c3996aa7f7afb49607ffff2b78 16773524 libpython3.11-dbg_3.11.2-6+deb12u2_amd64.deb d999532295cf67400f699bd28bbc9a21e515148f 4742212 libpython3.11-dev_3.11.2-6+deb12u2_amd64.deb ac854f34e5a72a71fabe3f8b6798fe024c936c04 814448 libpython3.11-minimal_3.11.2-6+deb12u2_amd64.deb 65e74ec277035fd51a36930b2be22d28bcee99bb 1799080 libpython3.11-stdlib_3.11.2-6+deb12u2_amd64.deb 83ae323224c9d031c0f9febacb1271d0e5b5b4ff 1986884 libpython3.11_3.11.2-6+deb12u2_amd64.deb 60aeec5c7330d590a955d702a8ea2086711c8aef 36963304 python3.11-dbg_3.11.2-6+deb12u2_amd64.deb 4c344808cec451a48a290aee62db51560e2ad502 614552 python3.11-dev_3.11.2-6+deb12u2_amd64.deb 1dc6e1c826765b38ddf39c0c5353199d3705a7c8 1292 python3.11-full_3.11.2-6+deb12u2_amd64.deb 793b97dd20cbdcb8a132065a5c92695b8f022beb 2067088 python3.11-minimal_3.11.2-6+deb12u2_amd64.deb 55e88674ec52831239f6e3b6fb4781eb69bd773e 2054232 python3.11-nopie_3.11.2-6+deb12u2_amd64.deb cafd70181b1f2faa020a50fb75282b49c968d470 5896 python3.11-venv_3.11.2-6+deb12u2_amd64.deb b7a15204a39f1a8c34dec90f369f09c2a65bcfe2 13400 python3.11_3.11.2-6+deb12u2_amd64-buildd.buildinfo 6c56ff2f880ecbe6cd7835ff73603b0f122860f1 572784 python3.11_3.11.2-6+deb12u2_amd64.deb Checksums-Sha256: cb955cb32f88cf95851701732e0f3aa5f1316379a349dd2de56d5ebc624c6cd1 16773524 libpython3.11-dbg_3.11.2-6+deb12u2_amd64.deb e4433285552f3573b2ed4acbda0370c0862e0a26879b465169bf013dd22a3802 4742212 libpython3.11-dev_3.11.2-6+deb12u2_amd64.deb 97abc912bde891d6b5e1e893c063070aba5bb4234df606193a8e998244e045ff 814448 libpython3.11-minimal_3.11.2-6+deb12u2_amd64.deb 690ebcebabc4c1c3558fc06e3266842f0f26f5d9c3ec0d37a6663d013ae78468 1799080 libpython3.11-stdlib_3.11.2-6+deb12u2_amd64.deb 3210a8d7640b1096a2bf4c6deaca27e92de2479b5853406caf75ffb0eff600a1 1986884 libpython3.11_3.11.2-6+deb12u2_amd64.deb 921939d7d0b4c420267e83bb42935e92686362d1f5f1dcc866f37a3b5c3e0239 36963304 python3.11-dbg_3.11.2-6+deb12u2_amd64.deb 4912eaf44da516d1a69070d90b862d51e7ca55ebc72d1390b96fc75e53385b87 614552 python3.11-dev_3.11.2-6+deb12u2_amd64.deb 6942217a2a09380ed5531bfdc705a2ab70076cbae7615f629f42ffd7c71f0ca7 1292 python3.11-full_3.11.2-6+deb12u2_amd64.deb c54fa106f753553fa5026ddbaec6194d72bff0a0769936e0ac34e26159218996 2067088 python3.11-minimal_3.11.2-6+deb12u2_amd64.deb 4b7fbaae0e22ce6d4fd5ab19ac3fc2e0c94dee7427bc05493f470b5119a67204 2054232 python3.11-nopie_3.11.2-6+deb12u2_amd64.deb 6553ed975b8c67691a460b30d4bcfb2e35d07efb9f0bd14fd32f726583d60565 5896 python3.11-venv_3.11.2-6+deb12u2_amd64.deb 3ea3eecc74db962035ce201bc1ae582c9acc999b9aebeb4a0a2f8217d1a606d1 13400 python3.11_3.11.2-6+deb12u2_amd64-buildd.buildinfo b04f4deeedd43858d3078b0dd27fbc23c662797a6f621019e4a89d842b7d38a3 572784 python3.11_3.11.2-6+deb12u2_amd64.deb Files: 9e4fe731899b95626f0d56c30e35b8eb 16773524 debug optional libpython3.11-dbg_3.11.2-6+deb12u2_amd64.deb 2fd0df77912ec0380df2838533f3677d 4742212 libdevel optional libpython3.11-dev_3.11.2-6+deb12u2_amd64.deb 8831aece65780fb2fb9ee42461efbba5 814448 python optional libpython3.11-minimal_3.11.2-6+deb12u2_amd64.deb 320b2694c052bfdc56c8bc65384c09ee 1799080 python optional libpython3.11-stdlib_3.11.2-6+deb12u2_amd64.deb 8a8dfc0fb16f099bf1d13609b6c9e07a 1986884 libs optional libpython3.11_3.11.2-6+deb12u2_amd64.deb 436d04384a870a079bbd7934a6a27128 36963304 debug optional python3.11-dbg_3.11.2-6+deb12u2_amd64.deb 0b19c1bf688cc1589561cd0df126957e 614552 python optional python3.11-dev_3.11.2-6+deb12u2_amd64.deb ab98b975c5f8d056eda720ed421e05a0 1292 python optional python3.11-full_3.11.2-6+deb12u2_amd64.deb 59cbbefe8fd575f4b2877af1ba67126b 2067088 python optional python3.11-minimal_3.11.2-6+deb12u2_amd64.deb fbdf6acb2f09591f2270217a8e5771d4 2054232 python optional python3.11-nopie_3.11.2-6+deb12u2_amd64.deb 407eb361cdbde3d3f41121bfa1d105d2 5896 python optional python3.11-venv_3.11.2-6+deb12u2_amd64.deb b8d3dd043595da6dbd91acbf9b48919b 13400 python optional python3.11_3.11.2-6+deb12u2_amd64-buildd.buildinfo 703a91bbd7a8a07712ce0e720f41eea4 572784 python optional python3.11_3.11.2-6+deb12u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmZL+OAACgkQ3KGKEAtj IVj9SA//ZANrn8Gaawf0Lu+ZvJdZ2Hu/Q0qErljL7NyJM4go6t93YZ1IMG0mzFYD Zr1Jwajbx54u3CLqiglznM6/zbdX052EBDAYKwdKKZR0TunHlWNU+olgqE2/hKC8 OdGhG6RC+mKPHMXE4EdaF13jyvHxgDXcQn+tJPe2QFcZy5SswYIkFBgXk63hkSQv rBbDbMfUMc39Gyap+L7vFWoSrJmyOGbVBKgduZaOsGOY9QAMkVl4R4JEHFd1j7ck LZyUwUbKdxgLSyEIcF6DDRLTkiyc4cTX1ErdIZQ8h7FSB/6n3C+tXsb6nOti1jm9 qEd2PBX75Td1bHGGQq/2a8LXrXnBBIQKkZd+IZw3+Nz8COCEZJCnt2oxX0ziWTmC VIBfy0f3DbnNg0YCkriZMCyLH+BoHPMSCN4s+6isVfJXoOxvVn8AOUqrWIB91A/U BV8oWsEmR2zRdB+rlS7/ch31J06xmyQrXdmqhZ/zBuN1p4+lgM4kEXCSt5MfooJn khveNvuMObWCsTObi1/HWgPnb1AvQxgjdvUanjctrb0Lv2Ha298N9yOqLN6f1WF1 0y++PSCi2Ng6nljAIFyg3i/DCiVMgITnww5CajSg2Xwmzv2IVvHyVBXXyk9NdJKX pa3ocf5ryFovmjQvX6CuupetyLaLymlwP0FIrlKRvqV1mCLzyOk= =FweL -----END PGP SIGNATURE-----