ELA-1066-1 python3.5 security update

quoted-overlap zipbomb DoS

2024-03-24
Packagepython3.5
Version3.5.3-1+deb9u9 (stretch)
Related CVEs CVE-2024-0450


The zipfile module was vulnerable to “quoted-overlap” zip-bombs in the Python 3 interpreter.



For Debian 9 stretch, these problems have been fixed in version 3.5.3-1+deb9u9.

We recommend that you upgrade your python3.5 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.