summaryrefslogtreecommitdiff
path: root/Misc/NEWS.d/3.8.12.rst
blob: b64613ae2f5ab1f6d43d59bc085849df9ba0a658 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
.. bpo: 42278
.. date: 2021-08-29-12-39-44
.. nonce: jvmQz_
.. release date: 2021-08-30
.. section: Security

Replaced usage of :func:`tempfile.mktemp` with
:class:`~tempfile.TemporaryDirectory` to avoid a potential race condition.

..

.. bpo: 44394
.. date: 2021-06-29-02-45-53
.. nonce: A220N1
.. section: Security

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the fix
for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy is most used
on Windows and macOS.

..

.. bpo: 43124
.. date: 2021-05-08-11-50-46
.. nonce: 2CTM6M
.. section: Security

Made the internal ``putcmd`` function in :mod:`smtplib` sanitize input for
presence of ``\r`` and ``\n`` characters to avoid (unlikely) command
injection.

..

.. bpo: 36384
.. date: 2021-03-30-16-29-51
.. nonce: sCAmLs
.. section: Security

:mod:`ipaddress` module no longer accepts any leading zeros in IPv4 address
strings. Leading zeros are ambiguous and interpreted as octal notation by
some libraries. For example the legacy function :func:`socket.inet_aton`
treats leading zeros as octal notation. glibc implementation of modern
:func:`~socket.inet_pton` does not accept any leading zeros. For a while the
:mod:`ipaddress` module used to accept ambiguous leading zeros.

..

.. bpo: 44872
.. date: 2021-08-09-16-16-03
.. nonce: OKRlhK
.. section: Core and Builtins

Use new trashcan macros (Py_TRASHCAN_BEGIN/END) in frameobject.c instead of
the old ones (Py_TRASHCAN_SAFE_BEGIN/END).

..

.. bpo: 33930
.. date: 2021-08-09-14-29-52
.. nonce: --5LQ-
.. section: Core and Builtins

Fix segmentation fault with deep recursion when cleaning method objects.
Patch by Augusto Goulart and Pablo Galindo.

..

.. bpo: 44856
.. date: 2021-08-07-01-26-12
.. nonce: 9rk3li
.. section: Core and Builtins

Fix reference leaks in the error paths of ``update_bases()`` and
``__build_class__``. Patch by Pablo Galindo.

..

.. bpo: 45001
.. date: 2021-08-26-16-25-48
.. nonce: tn_dKp
.. section: Library

Made email date parsing more robust against malformed input, namely a
whitespace-only ``Date:`` header. Patch by Wouter Bolsterlee.

..

.. bpo: 30511
.. date: 2021-07-20-21-03-18
.. nonce: eMFkRi
.. section: Documentation

Clarify that :func:`shutil.make_archive` is not thread-safe due to reliance
on changing the current working directory.

..

.. bpo: 45007
.. date: 2021-08-27-23-50-02
.. nonce: NIBlVG
.. section: Windows

Update to OpenSSL 1.1.1l in Windows build

..

.. bpo: 45007
.. date: 2021-08-30-00-04-10
.. nonce: pixqUB
.. section: macOS

Update macOS installer builds to use OpenSSL 1.1.1l.

..

.. bpo: 44689
.. date: 2021-07-20-22-27-01
.. nonce: mmT_xH
.. section: macOS

:meth:`ctypes.util.find_library` now works correctly on macOS 11 Big Sur
even if Python is built on an older version of macOS.  Previously, when
built on older macOS systems, ``find_library`` was not able to find  macOS
system libraries when running on Big Sur due to changes in  how system
libraries are stored.