Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
C
cpython
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
0
Merge Requests
0
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
Kirill Smelkov
cpython
Commits
4a865a35
Commit
4a865a35
authored
Jul 28, 2016
by
Victor Stinner
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
NEWS: tag security related changes with [Security] prefix
Issue #27404.
parent
3e5b1d3c
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
9 additions
and
9 deletions
+9
-9
Misc/NEWS
Misc/NEWS
+9
-9
No files found.
Misc/NEWS
View file @
4a865a35
...
...
@@ -86,14 +86,14 @@ Library
when
exiting
,
let
the
new
chained
one
through
.
This
avoids
the
PEP
479
bug
described
in
issue25782
.
-
Issue
#
27278
:
Fix
os
.
urandom
()
implementation
using
getrandom
()
on
Linux
.
-
[
Security
]
Issue
#
27278
:
Fix
os
.
urandom
()
implementation
using
getrandom
()
on
Linux
.
Truncate
size
to
INT_MAX
and
loop
until
we
collected
enough
random
bytes
,
instead
of
casting
a
directly
Py_ssize_t
to
int
.
-
Issue
#
26386
:
Fixed
ttk
.
TreeView
selection
operations
with
item
id
's
containing spaces.
- Issue #22636: Avoid shell injection problems with
-
[Security]
Issue #22636: Avoid shell injection problems with
ctypes.util.find_library().
- Issue #16182: Fix various functions in the "readline" module to use the
...
...
@@ -309,10 +309,10 @@ Core and Builtins
Library
-------
-
Issue
#
26556
:
Update
expat
to
2.1.1
,
fixes
CVE
-
2015
-
1283.
-
[
Security
]
Issue
#
26556
:
Update
expat
to
2.1.1
,
fixes
CVE
-
2015
-
1283.
-
Fix
TLS
stripping
vulnerability
in
smtplib
,
CVE
-
2016
-
0772.
Reported
by
Team
Oststrom
-
[
Security
]
Fix
TLS
stripping
vulnerability
in
smtplib
,
CVE
-
2016
-
0772.
Reported
by
Team
Oststrom
-
Issue
#
21386
:
Implement
missing
IPv4Address
.
is_global
property
.
It
was
documented
since
07
a5610bae9d
.
Initial
patch
by
Roger
Luethi
.
...
...
@@ -336,7 +336,7 @@ Library
-
Issue
#
21313
:
Fix
the
"platform"
module
to
tolerate
when
sys
.
version
contains
truncated
build
information
.
-
Issue
#
26839
:
On
Linux
,
:
func
:`
os
.
urandom
`
now
calls
``
getrandom
()``
with
-
[
Security
]
Issue
#
26839
:
On
Linux
,
:
func
:`
os
.
urandom
`
now
calls
``
getrandom
()``
with
``
GRND_NONBLOCK
``
to
fall
back
on
reading
``/
dev
/
urandom
``
if
the
urandom
entropy
pool
is
not
initialized
yet
.
Patch
written
by
Colm
Buckley
.
...
...
@@ -444,7 +444,7 @@ Library
-
Issue
#
24838
:
tarfile
's ustar and gnu formats now correctly calculate name
and link field limits for multibyte character encodings like utf-8.
- Issue #26657: Fix directory traversal vulnerability with http.server on
-
[Security]
Issue #26657: Fix directory traversal vulnerability with http.server on
Windows. This fixes a regression that was introduced in 3.3.4rc1 and
3.4.0rc1. Based on patch by Philipp Hagemeister.
...
...
@@ -493,7 +493,7 @@ Library
-
Issue
#
26560
:
Avoid
potential
ValueError
in
BaseHandler
.
start_response
.
Initial
patch
by
Peter
Inglesby
.
-
Issue
#
26313
:
ssl
.
py
_load_windows_store_certs
fails
if
windows
cert
store
-
[
Security
]
Issue
#
26313
:
ssl
.
py
_load_windows_store_certs
fails
if
windows
cert
store
is
empty
.
Patch
by
Baji
.
-
Issue
#
26569
:
Fix
:
func
:`
pyclbr
.
readmodule
`
and
:
func
:`
pyclbr
.
readmodule_ex
`
...
...
@@ -555,7 +555,7 @@ Library
the
connected
socket
)
when
verify_request
()
returns
false
.
Patch
by
Aviv
Palivoda
.
-
Issue
#
25939
:
On
Windows
open
the
cert
store
readonly
in
ssl
.
enum_certificates
.
-
[
Security
]
Issue
#
25939
:
On
Windows
open
the
cert
store
readonly
in
ssl
.
enum_certificates
.
-
Issue
#
25995
:
os
.
walk
()
no
longer
uses
FDs
proportional
to
the
tree
depth
.
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment