File _patchinfo of Package patchinfo.35246
<patchinfo incident="35246">
<issue tracker="cve" id="2024-6923"/>
<issue tracker="bnc" id="1228780">VUL-0: CVE-2024-6923: python,python3,python310,python311,python312,python36,python39: CPython : Email header injection due to unquoted newlines</issue>
<issue tracker="bnc" id="1225660">python311-pip package installs in /usr/lib by default</issue>
<issue tracker="bnc" id="1227378">/usr/bin/idle* don't have executable bits</issue>
<issue tracker="bnc" id="1227999">python reproducible builds</issue>
<packager>mcepl</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for python311</summary>
<description>This update for python311 fixes the following issues:
- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
Other fixes:
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
- Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378)
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
</description>
</patchinfo>