Opened 17 months ago
Closed 17 months ago
New point version.
Similar to LFS, promoting to Elevated due to security fixes:
bpo-42278: Replaced usage of tempfile.mktemp() with TemporaryDirectory
to avoid a potential race condition.
bpo-41180: Add auditing events to the marshal module, and stop raising
code.__init__ events for every unmarshalled code object. Directly
instantiated code objects will continue to raise an event, and audit event
handlers should inspect or collect the raw marshal data. This reduces a
significant performance overhead when loading from .pyc files.
bpo-44394: Update the vendored copy of libexpat to 2.4.1 (from 2.2.8)
to get the fix for the CVE-2013-0340 “Billion Laughs” vulnerability. This
copy is most used on Windows and macOS.
bpo-43124: Made the internal putcmd function in smtplib sanitize input
for presence of \r and \n characters to avoid (unlikely) command
Note that we already have the fix for CVE-2013-0340 in our version of Expat in LFS, so that does not affect us.
Fixed at commit cc1c942130b5032afd457ed09864f5ba4a70c74c
Update to Python3-3.9.7.
Update to libcap-2.57.
Powered by Trac 1.5.3.dev0
By Edgewall Software
© 1998-2022 Gerard Beekmans.