Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
package/python3: security bump to version 3.8.4
Fixes the following security issues: - bpo-41162: Audit hooks are now cleared later during finalization to avoid missing events. - bpo-29778: Ensure python3.dll is loaded from correct locations when Python is embedded (CVE-2020-15523). - bpo-41004: The __hash__() methods of ipaddress.IPv4Interface and ipaddress.IPv6Interface incorrectly generated constant hash values of 32 and 128 respectively. This resulted in always causing hash collisions. The fix uses hash() to generate hash values for the tuple of (address, mask length, network address). - bpo-39073: Disallow CR or LF in email.headerregistry.Address arguments to guard against header injection attacks. For more details, see the changelog: https://docs.python.org/release/3.8.4/whatsnew/changelog.html#security Signed-off-by: Adam Duskett <[email protected]> Signed-off-by: Yann E. MORIN <[email protected]> (cherry picked from commit d6ff343d67383df37c0e6f1f8ec64464a1be467b) [Peter: mention security impact] Signed-off-by: Peter Korsgaard <[email protected]>
- Loading branch information