File _patchinfo of Package patchinfo.35324
<patchinfo incident="35324"> <issue tracker="cve" id="2024-42367"/> <issue tracker="bnc" id="1229226">VUL-0: CVE-2024-42367: python-aiohttp: path traversal outside the root directory when requests involve compressed files (.gz or .br extensions) that are symbolic links</issue> <packager>StevenK</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for python-aiohttp</summary> <description>This update for python-aiohttp fixes the following issues: - CVE-2024-42367: Fixed path traversal outside the root directory when requests involve compressed files as symbolic links (bsc#1229226) </description> </patchinfo>