diff options
author | Christian Heimes <christian@cheimes.de> | 2013-02-25 12:08:29 +0100 |
---|---|---|
committer | Christian Heimes <christian@cheimes.de> | 2013-02-25 12:08:29 +0100 |
commit | 53bd6b4685a3c9171cc5c4080fceb0ea09208a61 (patch) | |
tree | ca7289cc8155cf38570360e00caa6e0de88c2ef0 | |
parent | c04243b70403332e5c132a5ffce97ce95631ad9f (diff) | |
download | defusedxml-53bd6b4685a3c9171cc5c4080fceb0ea09208a61.tar.gz |
prepare release 0.4#v0.4
-rw-r--r-- | CHANGES.txt | 5 | ||||
-rw-r--r-- | defusedxml/__init__.py | 2 |
2 files changed, 4 insertions, 3 deletions
diff --git a/CHANGES.txt b/CHANGES.txt index fe8f95b..321d67c 100644 --- a/CHANGES.txt +++ b/CHANGES.txt @@ -4,14 +4,15 @@ Changelog defusedxml 0.4 -------------- -*Release date: ??-???-2013* +*Release date: 25-Feb-2013* - As per http://seclists.org/oss-sec/2013/q1/340 please REJECT CVE-2013-0278, CVE-2013-0279 and CVE-2013-0280 and use CVE-2013-1664, CVE-2013-1665 for OpenStack/etc. - Add missing parser_list argument to sax.make_parser(). The argument is ignored, though. (thanks to Florian Apolloner) -- Add demo exploit for external entity attack on Python's SAX parser. +- Add demo exploit for external entity attack on Python's SAX parser, XML-RPC + and WebDAV. defusedxml 0.3 diff --git a/defusedxml/__init__.py b/defusedxml/__init__.py index be5d440..309313a 100644 --- a/defusedxml/__init__.py +++ b/defusedxml/__init__.py @@ -38,5 +38,5 @@ def defuse_stdlib(): return defused -__version__ = "0.3" +__version__ = "0.4" |