File _patchinfo of Package patchinfo.33618
<patchinfo incident="33618">
<issue tracker="cve" id="2023-6597"/>
<issue tracker="cve" id="2024-0450"/>
<issue tracker="cve" id="2023-52425"/>
<issue tracker="bnc" id="1221854">VUL-0: CVE-2024-0450: python: The zipfile module is vulnerable to "quoted-overlap"</issue>
<issue tracker="bnc" id="1219559">VUL-0: CVE-2023-52425: expat: denial of service (resource consumption) caused by processing large tokens</issue>
<issue tracker="bnc" id="1219666">VUL-0: CVE-2023-6597: python,python3,python310,python311,python36,python39: tempfile.TemporaryDirectory fails removing dir in some edge cases related to symlinks</issue>
<issue tracker="bnc" id="1221260">[SLEMicro6.0] python311 fails on SUSE:ALP:Source:Standard:Core:1.0:Build</issue>
<issue tracker="bnc" id="1189495">%autopatch missing -m and -M parameter</issue>
<issue tracker="bnc" id="1211301">crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages</issue>
<packager>mcepl</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for python311</summary>
<description>This update for python311 fixes the following issues:
- CVE-2024-0450: Fixed "quoted-overlap" issue inside the zipfile module (bsc#1221854).
- CVE-2023-6597: Fixed removing tempfile.TemporaryDirectory in some edge cases related to symlinks (bsc#1219666).
- CVE-2023-52425: Fixed denial of service (resource consumption) caused by processing large tokens (bsc#1219559).
Bug fixes:
- Eliminate ResourceWarning which broke the test suite in test_asyncio (bsc#1221260).
- Revert use of %autopatch (bsc#1189495).
- Use the system-wide crypto-policies (bsc#1211301).
</description>
</patchinfo>