<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/cpython-git.git, branch v3.5.6</title>
<subtitle>github.com: python/cpython.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/'/>
<entry>
<title>Version bump for 3.5.6 final.</title>
<updated>2018-08-02T09:19:12+00:00</updated>
<author>
<name>Larry Hastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-08-02T09:19:12+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=627d0c61ac96009450e3794a2401f244e56fcb79'/>
<id>627d0c61ac96009450e3794a2401f244e56fcb79</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add Blurb entry for 3.5.6 final.</title>
<updated>2018-08-02T09:16:53+00:00</updated>
<author>
<name>Larry Hastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-08-02T09:16:53+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=b86a50f8a04473822cda25dfcadad09e70f1d810'/>
<id>b86a50f8a04473822cda25dfcadad09e70f1d810</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Post-release version bump for 3.5.6rc1.</title>
<updated>2018-07-20T02:31:49+00:00</updated>
<author>
<name>Larry Hastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-07-20T02:31:49+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f497e7465621b2d092205868db6ab9261fbe467e'/>
<id>f497e7465621b2d092205868db6ab9261fbe467e</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Version bump for 3.5.6rc1.</title>
<updated>2018-07-20T00:57:25+00:00</updated>
<author>
<name>Larry Hastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-07-20T00:57:25+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=7df16b1d93d6213ff8ec5e9f5bc95ea7a3dd402f'/>
<id>7df16b1d93d6213ff8ec5e9f5bc95ea7a3dd402f</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>PyDoc topics refresh &amp; blurb release for 3.5.6rc1.</title>
<updated>2018-07-20T00:55:28+00:00</updated>
<author>
<name>Larry Hastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-07-20T00:55:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=95c6597a47295e7a77184feadcad8749d6198d5b'/>
<id>95c6597a47295e7a77184feadcad8749d6198d5b</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-33216: Clarify the documentation for CALL_FUNCTION_* (#8338)</title>
<updated>2018-07-19T23:35:28+00:00</updated>
<author>
<name>larryhastings</name>
<email>larry@hastings.org</email>
</author>
<published>2018-07-19T23:35:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=76aa2c0a9a8dd3ac90b91e7342c8ce8125bf21f9'/>
<id>76aa2c0a9a8dd3ac90b91e7342c8ce8125bf21f9</id>
<content type='text'>
Clarify the documentation for the CALL_FUNCTION_* bytecodes.  They changed in 3.5 in subtle ways and the documentation has never been correct, much less clear.</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Clarify the documentation for the CALL_FUNCTION_* bytecodes.  They changed in 3.5 in subtle ways and the documentation has never been correct, much less clear.</pre>
</div>
</content>
</entry>
<entry>
<title>Doc: Backport language switcher (bpo-33700, bpo-31045) (#8048)</title>
<updated>2018-07-02T19:56:28+00:00</updated>
<author>
<name>Julien Palard</name>
<email>julien@palard.fr</email>
</author>
<published>2018-07-02T19:56:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=1b141b9553424971639bde281feb1d4e4e586dbe'/>
<id>1b141b9553424971639bde281feb1d4e4e586dbe</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Backport 3.7.0 final changes</title>
<updated>2018-06-27T22:49:31+00:00</updated>
<author>
<name>Ned Deily</name>
<email>nad@python.org</email>
</author>
<published>2018-06-27T22:49:31+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=13402fc4c974b901c29d98e18301a6e41149508a'/>
<id>13402fc4c974b901c29d98e18301a6e41149508a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>[3.5] bpo-33001: Prevent buffer overrun in os.symlink (GH-5989) (#5991)</title>
<updated>2018-05-14T18:03:17+00:00</updated>
<author>
<name>Steve Dower</name>
<email>steve.dower@microsoft.com</email>
</author>
<published>2018-05-14T18:03:17+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f381cfe07d15d52f27de771a62a8167668f0dd51'/>
<id>f381cfe07d15d52f27de771a62a8167668f0dd51</id>
<content type='text'>
* bpo-33001: Minimal fix to prevent buffer overrun in os.symlink

* Remove invalid test
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* bpo-33001: Minimal fix to prevent buffer overrun in os.symlink

* Remove invalid test
</pre>
</div>
</content>
</entry>
<entry>
<title>[3.5] bpo-32981: Fix catastrophic backtracking vulns (GH-5955) (#6034)</title>
<updated>2018-03-11T18:29:05+00:00</updated>
<author>
<name>Ned Deily</name>
<email>nad@python.org</email>
</author>
<published>2018-03-11T18:29:05+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=937ac1fe069a4dc8471dff205f553d82e724015b'/>
<id>937ac1fe069a4dc8471dff205f553d82e724015b</id>
<content type='text'>
* Prevent low-grade poplib REDOS (CVE-2018-1060)

The regex to test a mail server's timestamp is susceptible to
catastrophic backtracking on long evil responses from the server.

Happily, the maximum length of malicious inputs is 2K thanks
to a limit introduced in the fix for CVE-2013-1752.

A 2KB evil response from the mail server would result in small slowdowns
(milliseconds vs. microseconds) accumulated over many apop calls.
This is a potential DOS vector via accumulated slowdowns.

Replace it with a similar non-vulnerable regex.

The new regex is RFC compliant.
The old regex was non-compliant in edge cases.

* Prevent difflib REDOS (CVE-2018-1061)

The default regex for IS_LINE_JUNK is susceptible to
catastrophic backtracking.
This is a potential DOS vector.

Replace it with an equivalent non-vulnerable regex.

Also introduce unit and REDOS tests for difflib.

Co-authored-by: Tim Peters &lt;tim.peters@gmail.com&gt;
Co-authored-by: Christian Heimes &lt;christian@python.org&gt;.
(cherry picked from commit 0e6c8ee2358a2e23117501826c008842acb835ac)</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* Prevent low-grade poplib REDOS (CVE-2018-1060)

The regex to test a mail server's timestamp is susceptible to
catastrophic backtracking on long evil responses from the server.

Happily, the maximum length of malicious inputs is 2K thanks
to a limit introduced in the fix for CVE-2013-1752.

A 2KB evil response from the mail server would result in small slowdowns
(milliseconds vs. microseconds) accumulated over many apop calls.
This is a potential DOS vector via accumulated slowdowns.

Replace it with a similar non-vulnerable regex.

The new regex is RFC compliant.
The old regex was non-compliant in edge cases.

* Prevent difflib REDOS (CVE-2018-1061)

The default regex for IS_LINE_JUNK is susceptible to
catastrophic backtracking.
This is a potential DOS vector.

Replace it with an equivalent non-vulnerable regex.

Also introduce unit and REDOS tests for difflib.

Co-authored-by: Tim Peters &lt;tim.peters@gmail.com&gt;
Co-authored-by: Christian Heimes &lt;christian@python.org&gt;.
(cherry picked from commit 0e6c8ee2358a2e23117501826c008842acb835ac)</pre>
</div>
</content>
</entry>
</feed>
