← Search the atlas
SUSE-SU-2024:3200-1
Not scored
Security update for python311
This update for python311 fixes the following issues:
- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
Other fixes:
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
- Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378)
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
Exploit probability
Not scored
Published
September 11, 2024
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-documentation
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
python311
SUSE:Linux Enterprise Module for Public Cloud 15 SP4
python311-core
SUSE:Linux Enterprise Module for Python 3 15 SP5
python311
SUSE:Linux Enterprise Module for Python 3 15 SP5
python311-core
SUSE:Linux Enterprise Module for Python 3 15 SP5
python311-documentation
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-core
SUSE:Linux Enterprise Server 15 SP4-LTSS
python311-documentation
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-core
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
python311-documentation
openSUSE:Leap 15.5
python311
openSUSE:Leap 15.5
python311-core
openSUSE:Leap 15.5
python311-documentation
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2024:3200-1
This update for python311 fixes the following issues:
- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
Other fixes:
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
- Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378)
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
View original source ↗
05 / REFERENCES
Further evidence