<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/cpython-git.git, branch backport-52d1b86-3.6</title>
<subtitle>github.com: python/cpython.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/'/>
<entry>
<title>[3.6] bpo-38301: In Solaris family, we must be sure to use '-D_REENTRANT' (GH-16446).</title>
<updated>2019-09-28T02:16:55+00:00</updated>
<author>
<name>Jesús Cea</name>
<email>jcea@jcea.es</email>
</author>
<published>2019-09-28T01:44:32+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=cbf04fd2a519ed0560d1b04cd24c43e9d8086c87'/>
<id>cbf04fd2a519ed0560d1b04cd24c43e9d8086c87</id>
<content type='text'>
(cherry picked from commit 52d1b86bde2b772a76919c76991c326384954bf1)

Co-authored-by: Jesús Cea &lt;jcea@jcea.es&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit 52d1b86bde2b772a76919c76991c326384954bf1)

Co-authored-by: Jesús Cea &lt;jcea@jcea.es&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>[3.6] closes bpo-38174: Update vendored expat library to 2.2.8. (GH-16410)</title>
<updated>2019-09-26T05:00:26+00:00</updated>
<author>
<name>Benjamin Peterson</name>
<email>benjamin@python.org</email>
</author>
<published>2019-09-26T05:00:26+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f0501630b0ba31448c230c756b1027647f4ef100'/>
<id>f0501630b0ba31448c230c756b1027647f4ef100</id>
<content type='text'>
Fixes CVE-2019-15903. See full changelog at https://github.com/libexpat/libexpat/blob/R_2_2_8/expat/Changes..
(cherry picked from commit 52b940803860e37bcc3f6096b2d24e7c20a0e807)</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fixes CVE-2019-15903. See full changelog at https://github.com/libexpat/libexpat/blob/R_2_2_8/expat/Changes..
(cherry picked from commit 52b940803860e37bcc3f6096b2d24e7c20a0e807)</pre>
</div>
</content>
</entry>
<entry>
<title>[3.6] bpo-37461: Fix typo (inifite -&gt; infinite) (#15432)</title>
<updated>2019-08-24T04:33:36+00:00</updated>
<author>
<name>GeeTransit</name>
<email>geetransit@gmail.com</email>
</author>
<published>2019-08-24T04:33:36+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f1f9c0c532089824791cfc18e6d6f29e1cd62596'/>
<id>f1f9c0c532089824791cfc18e6d6f29e1cd62596</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-34155: Dont parse domains containing @ (GH-13079) (GH-14826)</title>
<updated>2019-08-09T15:22:19+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2019-08-09T15:22:19+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=13a19139b5e76175bc95294d54afc9425e4f36c9'/>
<id>13a19139b5e76175bc95294d54afc9425e4f36c9</id>
<content type='text'>
Before:

        &gt;&gt;&gt; email.message_from_string('From: a@malicious.org@important.com', policy=email.policy.default)['from'].addresses
        (Address(display_name='', username='a', domain='malicious.org'),)

        &gt;&gt;&gt; parseaddr('a@malicious.org@important.com')
        ('', 'a@malicious.org')

    After:

        &gt;&gt;&gt; email.message_from_string('From: a@malicious.org@important.com', policy=email.policy.default)['from'].addresses
        (Address(display_name='', username='', domain=''),)

        &gt;&gt;&gt; parseaddr('a@malicious.org@important.com')
        ('', 'a@')

https://bugs.python.org/issue34155
(cherry picked from commit 8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9)

Co-authored-by: jpic &lt;jpic@users.noreply.github.com&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Before:

        &gt;&gt;&gt; email.message_from_string('From: a@malicious.org@important.com', policy=email.policy.default)['from'].addresses
        (Address(display_name='', username='a', domain='malicious.org'),)

        &gt;&gt;&gt; parseaddr('a@malicious.org@important.com')
        ('', 'a@malicious.org')

    After:

        &gt;&gt;&gt; email.message_from_string('From: a@malicious.org@important.com', policy=email.policy.default)['from'].addresses
        (Address(display_name='', username='', domain=''),)

        &gt;&gt;&gt; parseaddr('a@malicious.org@important.com')
        ('', 'a@')

https://bugs.python.org/issue34155
(cherry picked from commit 8cb65d1381b027f0b09ee36bfed7f35bb4dec9a9)

Co-authored-by: jpic &lt;jpic@users.noreply.github.com&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-37461: Fix infinite loop in parsing of specially crafted email headers (GH-14794) (GH-14817)</title>
<updated>2019-08-01T16:36:46+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2019-08-01T16:36:46+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=1789bbdd3e03023951a39933ef12dee0a03be616'/>
<id>1789bbdd3e03023951a39933ef12dee0a03be616</id>
<content type='text'>
Some crafted email header would cause the get_parameter method to run in an
infinite loop causing a DoS attack surface when parsing those headers. This
patch fixes that by making sure the DQUOTE character is handled to prevent
going into an infinite loop.
(cherry picked from commit a4a994bd3e619cbaff97610a1cee8ffa87c672f5)

Co-authored-by: Abhilash Raj &lt;maxking@users.noreply.github.com&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Some crafted email header would cause the get_parameter method to run in an
infinite loop causing a DoS attack surface when parsing those headers. This
patch fixes that by making sure the DQUOTE character is handled to prevent
going into an infinite loop.
(cherry picked from commit a4a994bd3e619cbaff97610a1cee8ffa87c672f5)

Co-authored-by: Abhilash Raj &lt;maxking@users.noreply.github.com&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>Fix infinite loop in email folding logic (GH-12732) (GH-14799)</title>
<updated>2019-07-21T14:01:43+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2019-07-21T14:01:43+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=79a47e2b9cff6c9facdbc022a752177ab89dc533'/>
<id>79a47e2b9cff6c9facdbc022a752177ab89dc533</id>
<content type='text'>
As far as I can tell, this infinite loop would be triggered if:

1. The value being folded contains a single word (no spaces) longer than
   max_line_length
2. The max_line_length is shorter than the encoding's name + 9
   characters.

bpo-36564: https://bugs.python.org/issue36564
(cherry picked from commit f69d5c61981ea97d251db515c7ff280fcc17182d)

Co-authored-by: Paul Ganssle &lt;pganssle@users.noreply.github.com&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
As far as I can tell, this infinite loop would be triggered if:

1. The value being folded contains a single word (no spaces) longer than
   max_line_length
2. The max_line_length is shorter than the encoding's name + 9
   characters.

bpo-36564: https://bugs.python.org/issue36564
(cherry picked from commit f69d5c61981ea97d251db515c7ff280fcc17182d)

Co-authored-by: Paul Ganssle &lt;pganssle@users.noreply.github.com&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-37149: Replace dead link for online Tkinter reference  (GH-14616)</title>
<updated>2019-07-08T16:50:54+00:00</updated>
<author>
<name>Ned Deily</name>
<email>nad@python.org</email>
</author>
<published>2019-07-08T16:50:54+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=317c33e67cb6076c5a87a66c75e8c35ac581398d'/>
<id>317c33e67cb6076c5a87a66c75e8c35ac581398d</id>
<content type='text'>
Also fix a name misspelling.

Co-authored-by: Terry Jan Reedy &lt;tjreedy@udel.edu&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Also fix a name misspelling.

Co-authored-by: Terry Jan Reedy &lt;tjreedy@udel.edu&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix 3.6 documentation build for sphinx&lt;1.6 (GH-14576)</title>
<updated>2019-07-03T22:39:48+00:00</updated>
<author>
<name>Anthony Sottile</name>
<email>asottile@umich.edu</email>
</author>
<published>2019-07-03T22:39:49+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=a6d97e200863e7e5fc60bbc8f121b86a2098ef2d'/>
<id>a6d97e200863e7e5fc60bbc8f121b86a2098ef2d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Post release updates</title>
<updated>2019-07-02T21:57:03+00:00</updated>
<author>
<name>Ned Deily</name>
<email>nad@python.org</email>
</author>
<published>2019-07-02T21:57:03+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=af9e126a50eb0317f45e995fb3b32fdda48706bc'/>
<id>af9e126a50eb0317f45e995fb3b32fdda48706bc</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>3.6.9</title>
<updated>2019-07-02T20:25:39+00:00</updated>
<author>
<name>Ned Deily</name>
<email>nad@python.org</email>
</author>
<published>2019-07-02T20:25:39+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=201c8f79450628241574fba940e08107178dc3a5'/>
<id>201c8f79450628241574fba940e08107178dc3a5</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
