{"schema_version":"1.7.3","id":"SUSE-SU-2025:02297-1","published":"2025-07-11T16:03:54Z","modified":"2026-02-04T03:23:48.313181Z","related":["CVE-2024-12718","CVE-2025-4138","CVE-2025-4330","CVE-2025-4435","CVE-2025-4516","CVE-2025-4517","CVE-2025-6069"],"upstream":["CVE-2024-12718","CVE-2025-4138","CVE-2025-4330","CVE-2025-4435","CVE-2025-4516","CVE-2025-4517","CVE-2025-6069"],"summary":"Security update for python36","details":"This update for python36 fixes the following issues:\n\n- CVE-2024-12718: Fixed extraction filter bypass that allowed file metadata modification outside extraction directory (bsc#1244056)                                                           \n- CVE-2025-4138: Fixed issue that might allow symlink targets to point outside the destination directory, and the modification of some file metadata (bsc#1244059)                            \n- CVE-2025-4330: Fixed extraction filter bypass that allowed linking outside extraction directory (bsc#1244060)                                                                               \n- CVE-2025-4435: Fixed Tarfile extracts filtered members when errorlevel=0 (bsc#1244061)       \n- CVE-2025-4516: Fixed denial of service due to DecodeError handling vulnerability (bsc#1243273)\n- CVE-2025-4517: Fixed arbitrary filesystem writes outside the extraction directory during extraction with filter='data' (bsc#1244032)                                                        \n- CVE-2025-6069: Fixed worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705)                                                         \n\nOther fixes:\n- Add python36-* provides/obsoletes to enable SLE-12 -> SLE-15\n  migration (bsc#1233012)\n- Update vendored ipaddress module to 3.8 equivalent\n- Limit buffer size for IPv6 address parsing (bsc#1244401).\n","affected":[{"package":{"name":"python36","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-84.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_6m1_0":"3.6.15-84.1","libpython3_6m1_0-32bit":"3.6.15-84.1","python36":"3.6.15-84.1","python36-base":"3.6.15-84.1","python36-devel":"3.6.15-84.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02297-1.json"}},{"package":{"name":"python36-core","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-84.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_6m1_0":"3.6.15-84.1","libpython3_6m1_0-32bit":"3.6.15-84.1","python36":"3.6.15-84.1","python36-base":"3.6.15-84.1","python36-devel":"3.6.15-84.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02297-1.json"}},{"package":{"name":"python36","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-84.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_6m1_0":"3.6.15-84.1","libpython3_6m1_0-32bit":"3.6.15-84.1","python36":"3.6.15-84.1","python36-base":"3.6.15-84.1","python36-devel":"3.6.15-84.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02297-1.json"}},{"package":{"name":"python36-core","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.15-84.1"}]}],"ecosystem_specific":{"binaries":[{"libpython3_6m1_0":"3.6.15-84.1","libpython3_6m1_0-32bit":"3.6.15-84.1","python36":"3.6.15-84.1","python36-base":"3.6.15-84.1","python36-devel":"3.6.15-84.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:02297-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202502297-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1233012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243273"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244032"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244056"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244061"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244401"},{"type":"REPORT","url":"https://bugzilla.suse.com/1244705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-12718"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4435"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-4517"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-6069"}]}