#12244 closed enhancement (fixed)
python3-3.7.4
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | high | Milestone: | 9.0 |
| Component: | BOOK | Version: | SVN |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 7 years ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 7 years ago
comment:4 by , 7 years ago
| Priority: | normal → high |
|---|
bpo-30458: Address CVE-2019-9740 by disallowing URL paths with embedded whitespace or control characters through into the underlying http client request. Such potentially malicious header injection URLs now cause an http.client.InvalidURL exception to be raised.
bpo-35907: CVE-2019-9948: Avoid file reading by disallowing local-file:// and local_file:// URL schemes in URLopener().open() and URLopener().retrieve() of :mod:urllib.request.
Retroactively promote to High
Note:
See TracTickets
for help on using tickets.

What's New in Python 3.7.4 final?
*Release date: 2019-07-08*
Core and Builtins
1875in 3.7.4rc1 to check for syntax errors in dead conditional code blocks.Documentation
What's New in Python 3.7.4 release candidate 2?
Security
Core and Builtins
Library
_uuidheaders conflicting included.Windows
sys.executablewhen running from the Microsoft Store.macOS
What's New in Python 3.7.4 release candidate 1?
Security
local-file://andlocal_file://URL schemes inURLopener().open()andURLopener().retrieve()of :mod:urllib.request.shutil.whichnow usesos.confstr("CS_PATH")if available and if the :envvar:PATHenvironment variable is not set. Remove also the current directory from :data:posixpath.defpath. On Unix, :func:shutil.whichand the :mod:subprocessmodule no longer search the executable in the current directory if the :envvar:PATHenvironment variable is not set.Core and Builtins
wrap_lenfunc()whensizeof(long) < sizeof(Py_ssize_t)(e.g., 64-bit Windows).sys.stderrwhile using it. Document that an exception must be set when calling :c:func:`PyErr_WriteUnraisable`.f(kwargs)) and changing the dictkwargswhile that function is running.PyGC_Headstructure is aligned tolong double. This is needed to ensure GC-ed objects are aligned properly. Patch by Inada Naoki.SyntaxErroris now raised if a code blocks that will be optimized away (e.g. if conditions that are always false) contains syntax errors. Patch by Pablo Galindo. (Reverted in 3.7.4 final by :issue:37500.)PyCArrayType_new().PyMem_FREE()due to tokenizer.c'stok_nextc().itertools.count.ParserErrormessages, instead of numeric IDs. Patch by A. Skrobov.PyCArrayType_new().sys.pathif it has been removed._Py_dg_strtod()used byfloat(str),complex(str), :func:pickle.load, :func:marshal.load, etc.picklemodule. Patch by Zackery Spytz.PyInterpreterState_New().More. See Misc/NEWS in tarball.