UbuntuUpdates.org

Package "python-eventlet"

Name: python-eventlet

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • concurrent networking library - doc
  • concurrent networking library

Latest version: 0.30.2-5ubuntu2.2
Release: jammy (22.04)
Level: security
Repository: main

Links



Other versions of "python-eventlet" in Jammy

Repository Area Version
base main 0.30.2-5ubuntu2
updates main 0.30.2-5ubuntu2.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.30.2-5ubuntu2.2 2025-09-24 22:07:08 UTC

  python-eventlet (0.30.2-5ubuntu2.2) jammy-security; urgency=medium

  * SECURITY UPDATE: HTTP Request smuggling
    - debian/patches/CVE-2025-58068.patch: Fix request smuggling
      vulnerability by discarding trailers in eventlet/wsgi.py.
    - debian/patches/fixing_tests.py: shrinks window before connecting
      in tests/greenio_test.py. This test was causing a FTBFS (LP: #2125423).
    - CVE-2025-58068

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 15 Sep 2025 15:03:56 -0300

2125423 python-eventlet FTBFS due test failing
CVE-2025-58068 Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due



About   -   Send Feedback to @ubuntu_updates