Debian alert DLA-4377-1 (python-gevent)
| From: | Paride Legovini <paride@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4377-1] python-gevent security update | |
| Date: | Mon, 24 Nov 2025 22:50:31 +0100 | |
| Message-ID: | <daaef62cb790d7eb6d31114e480f3f99@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4377-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Paride Legovini November 24, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-gevent Version : 20.9.0-2+deb11u1 CVE ID : CVE-2023-41419 An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component. For Debian 11 bullseye, this problem has been fixed in version 20.9.0-2+deb11u1. We recommend that you upgrade your python-gevent packages. For the detailed security status of python-gevent please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-gevent Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- wsC7BAEBCgBvBYJpJNMdCRDWWGGIPgFNuUcUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmdUOQuED9Y87jUXZVbSFs0XZdwqQReU8o3vSnsg6cXx pxYhBFYa1YXu12aSG6jdltZYYYg+AU25AADHSwf/TVtZ1mBsZKGBzKiPs3KCJAWY QcqhOhwzDjO90w487e/GXACEwE/ZRupcm9ajR49gopAWqehkPAO55VtdHS4+xoHF e3MtFfBu4UvYRYW611VWhOq7HSywv3JzhTXWG43/3OhirzQO1ndi2hyi8jHDB7dp YdKcM2rW2HO1cuK+Ct+ofCnz19wkDVrrxSBhnZyObIo6mJeijGjcdOmX0dC51A0g g9BM1MW1FZzFUraqS/B1w/sbEdxcJW/eTM1ixBZpjVHPkfzKFwgZBEL7mAFvyFlq d85SmNfIz/LbMehPE604QJEzD6VPsKb/rmdPGagp1vk/TSMLIMMmqefn14o8GA== =hkn8 -----END PGP SIGNATURE-----
