File _patchinfo of Package patchinfo.35246

<patchinfo incident="35246">
  <issue tracker="cve" id="2024-6923"/>
  <issue tracker="bnc" id="1228780">VUL-0: CVE-2024-6923: python,python3,python310,python311,python312,python36,python39: CPython : Email header injection due to unquoted newlines</issue>
  <issue tracker="bnc" id="1225660">python311-pip package installs in /usr/lib by default</issue>
  <issue tracker="bnc" id="1227378">/usr/bin/idle* don't have executable bits</issue>
  <issue tracker="bnc" id="1227999">python reproducible builds</issue>
  <packager>mcepl</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python311</summary>
  <description>This update for python311 fixes the following issues:

- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)

Other fixes:
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
- Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378) 
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
</description>
</patchinfo>
openSUSE Build Service is sponsored by