File _patchinfo of Package patchinfo.35267

<patchinfo incident="35267">
  <issue tracker="cve" id="2023-27043"/>
  <issue tracker="cve" id="2024-0397"/>
  <issue tracker="cve" id="2024-6923"/>
  <issue tracker="cve" id="2024-4032"/>
  <issue tracker="bnc" id="1226448">VUL-0: CVE-2024-4032: python,python3,python310,python311,python312,python36,python39: incorrect IPv4 and IPv6 private ranges</issue>
  <issue tracker="bnc" id="1227999">python reproducible builds</issue>
  <issue tracker="bnc" id="1225660">python311-pip package installs in /usr/lib by default</issue>
  <issue tracker="bnc" id="1226447">VUL-0: CVE-2024-0397: python,python3,python310,python311,python312,python36,python39: memory race condition in ssl.SSLContext certificate store methods</issue>
  <issue tracker="bnc" id="1228780">VUL-0: CVE-2024-6923: python,python3,python310,python311,python312,python36,python39: CPython : Email header injection due to unquoted newlines</issue>
  <issue tracker="bnc" id="1227378">/usr/bin/idle* don't have executable bits</issue>
  <packager>mcepl</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python311</summary>
  <description>This update for python311 fixes the following issues:

Security issues fixed:

- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
- CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233)
- CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448)

Non-security issues fixed:

- Fixed executable bits for /usr/bin/idle* (bsc#1227378).
- Improve python reproducible builds (bsc#1227999)
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
</description>
</patchinfo>
openSUSE Build Service is sponsored by