Opened 8 months ago

Closed 8 months ago

#22754 closed enhancement (fixed)

python3-3.14.3 (Wait for LFS)

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by Xi Ruoyao, 8 months ago

The sed should be removed. Note that the upstream change added the inserted line into a different location so it may not seem obvious.

BTW I'd propose we must put a reference to the upstream ticket/change when adding a patch or sed (in the patch file, or XML comment, or the Git commit message). Otherwise it will be so time-wasting to investigate a case like this one.

comment:2 by Douglas R. Reno, 8 months ago

I 100% agree with you there, not only for time consuming searches like this one, but also so that we know where to look in the event of a security issue that gets caused by the sed/patch/etc.

comment:3 by Bruce Dubbs, 8 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:4 by Douglas R. Reno, 8 months ago

Priority: normal → elevated

Security changes for Python-3.14.3:

Security

    gh-144125: BytesGenerator will now refuse to serialize (write) headers that are 
unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas 
Bloemsaat and Petr Viktorin in gh-121650).

    gh-143935: Fixed a bug in the folding of comments when flattening an email message 
using a modern email policy. Comments consisting of a very long sequence of non-foldable 
characters could trigger a forced line wrap that omitted the required leading space on 
the continuation line, causing the remainder of the comment to be interpreted as a new 
header field. This enabled header injection with carefully crafted inputs.

    gh-143925: Reject control characters in data: URL media types.

    gh-143919: Reject control characters in http.cookies.Morsel fields and values.

    gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, 
values, and parameters.

comment:5 by Bruce Dubbs, 8 months ago

There are too many changes in this version to post here. See Python-3.14.3/Misc/NEWS in the tarball for the full list.

comment:6 by Bruce Dubbs, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

fc6f531da1 Update to Python-3.14.3.
5671b237b7 Update to shadow-4.19.3.
Note: See TracTickets for help on using tickets.