summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Heimes <christian@cheimes.de>2013-02-25 12:08:29 +0100
committerChristian Heimes <christian@cheimes.de>2013-02-25 12:08:29 +0100
commit53bd6b4685a3c9171cc5c4080fceb0ea09208a61 (patch)
treeca7289cc8155cf38570360e00caa6e0de88c2ef0
parentc04243b70403332e5c132a5ffce97ce95631ad9f (diff)
downloaddefusedxml-53bd6b4685a3c9171cc5c4080fceb0ea09208a61.tar.gz
prepare release 0.4#v0.4
-rw-r--r--CHANGES.txt5
-rw-r--r--defusedxml/__init__.py2
2 files changed, 4 insertions, 3 deletions
diff --git a/CHANGES.txt b/CHANGES.txt
index fe8f95b..321d67c 100644
--- a/CHANGES.txt
+++ b/CHANGES.txt
@@ -4,14 +4,15 @@ Changelog
defusedxml 0.4
--------------
-*Release date: ??-???-2013*
+*Release date: 25-Feb-2013*
- As per http://seclists.org/oss-sec/2013/q1/340 please REJECT
CVE-2013-0278, CVE-2013-0279 and CVE-2013-0280 and use CVE-2013-1664,
CVE-2013-1665 for OpenStack/etc.
- Add missing parser_list argument to sax.make_parser(). The argument is
ignored, though. (thanks to Florian Apolloner)
-- Add demo exploit for external entity attack on Python's SAX parser.
+- Add demo exploit for external entity attack on Python's SAX parser, XML-RPC
+ and WebDAV.
defusedxml 0.3
diff --git a/defusedxml/__init__.py b/defusedxml/__init__.py
index be5d440..309313a 100644
--- a/defusedxml/__init__.py
+++ b/defusedxml/__init__.py
@@ -38,5 +38,5 @@ def defuse_stdlib():
return defused
-__version__ = "0.3"
+__version__ = "0.4"