|
| 1 | +.. bpo: 26556 |
| 2 | +.. date: 9636 |
| 3 | +.. nonce: v5j2uL |
| 4 | +.. release date: 2016-06-12 |
| 5 | +.. original section: Library |
| 6 | +.. section: Security |
| 7 | +
|
| 8 | +Update expat to 2.1.1, fixes CVE-2015-1283. |
| 9 | + |
| 10 | +.. |
| 11 | +
|
| 12 | +.. bpo: 0 |
| 13 | +.. date: 9635 |
| 14 | +.. nonce: E4ochz |
| 15 | +.. original section: Library |
| 16 | +.. section: Security |
| 17 | +
|
| 18 | +Fix TLS stripping vulnerability in smtplib, CVE-2016-0772. Reported by Team |
| 19 | +Oststrom |
| 20 | + |
| 21 | +.. |
| 22 | +
|
| 23 | +.. bpo: 26839 |
| 24 | +.. date: 9629 |
| 25 | +.. nonce: yVvy7R |
| 26 | +.. original section: Library |
| 27 | +.. section: Security |
| 28 | +
|
| 29 | +On Linux, :func:`os.urandom` now calls ``getrandom()`` with |
| 30 | +``GRND_NONBLOCK`` to fall back on reading ``/dev/urandom`` if the urandom |
| 31 | +entropy pool is not initialized yet. Patch written by Colm Buckley. |
| 32 | + |
| 33 | +.. |
| 34 | +
|
| 35 | +.. bpo: 26657 |
| 36 | +.. date: 9597 |
| 37 | +.. nonce: C_-XFg |
| 38 | +.. original section: Library |
| 39 | +.. section: Security |
| 40 | +
|
| 41 | +Fix directory traversal vulnerability with http.server on Windows. This |
| 42 | +fixes a regression that was introduced in 3.3.4rc1 and 3.4.0rc1. Based on |
| 43 | +patch by Philipp Hagemeister. |
| 44 | + |
| 45 | +.. |
| 46 | +
|
| 47 | +.. bpo: 26313 |
| 48 | +.. date: 9581 |
| 49 | +.. nonce: LjZAjy |
| 50 | +.. original section: Library |
| 51 | +.. section: Security |
| 52 | +
|
| 53 | +ssl.py _load_windows_store_certs fails if windows cert store is empty. Patch |
| 54 | +by Baji. |
| 55 | + |
| 56 | +.. |
| 57 | +
|
| 58 | +.. bpo: 25939 |
| 59 | +.. date: 9561 |
| 60 | +.. nonce: X49Fqd |
| 61 | +.. original section: Library |
| 62 | +.. section: Security |
| 63 | +
|
| 64 | +On Windows open the cert store readonly in ssl.enum_certificates. |
| 65 | + |
| 66 | +.. |
| 67 | +
|
1 | 68 | .. bpo: 27066 |
2 | 69 | .. date: 9673 |
3 | 70 | .. nonce: SNExZi |
4 | | -.. release date: 2016-06-12 |
5 | 71 | .. section: Core and Builtins |
6 | 72 |
|
7 | 73 | Fixed SystemError if a custom opener (for open()) returns a negative number |
@@ -373,27 +439,6 @@ PendingDeprecationWarning. |
373 | 439 |
|
374 | 440 | .. |
375 | 441 |
|
376 | | -.. bpo: 26556 |
377 | | -.. date: 9636 |
378 | | -.. nonce: v5j2uL |
379 | | -.. original section: Library |
380 | | -.. section: Security |
381 | | -
|
382 | | -Update expat to 2.1.1, fixes CVE-2015-1283. |
383 | | - |
384 | | -.. |
385 | | -
|
386 | | -.. bpo: 0 |
387 | | -.. date: 9635 |
388 | | -.. nonce: E4ochz |
389 | | -.. original section: Library |
390 | | -.. section: Security |
391 | | -
|
392 | | -Fix TLS stripping vulnerability in smtplib, CVE-2016-0772. Reported by Team |
393 | | -Oststrom |
394 | | - |
395 | | -.. |
396 | | -
|
397 | 442 | .. bpo: 21386 |
398 | 443 | .. date: 9634 |
399 | 444 | .. nonce: DjV72U |
@@ -449,18 +494,6 @@ build information. |
449 | 494 |
|
450 | 495 | .. |
451 | 496 |
|
452 | | -.. bpo: 26839 |
453 | | -.. date: 9629 |
454 | | -.. nonce: yVvy7R |
455 | | -.. original section: Library |
456 | | -.. section: Security |
457 | | -
|
458 | | -On Linux, :func:`os.urandom` now calls ``getrandom()`` with |
459 | | -``GRND_NONBLOCK`` to fall back on reading ``/dev/urandom`` if the urandom |
460 | | -entropy pool is not initialized yet. Patch written by Colm Buckley. |
461 | | - |
462 | | -.. |
463 | | -
|
464 | 497 | .. bpo: 27164 |
465 | 498 | .. date: 9628 |
466 | 499 | .. nonce: 6wmjx2 |
@@ -776,18 +809,6 @@ limits for multibyte character encodings like utf-8. |
776 | 809 |
|
777 | 810 | .. |
778 | 811 |
|
779 | | -.. bpo: 26657 |
780 | | -.. date: 9597 |
781 | | -.. nonce: C_-XFg |
782 | | -.. original section: Library |
783 | | -.. section: Security |
784 | | -
|
785 | | -Fix directory traversal vulnerability with http.server on Windows. This |
786 | | -fixes a regression that was introduced in 3.3.4rc1 and 3.4.0rc1. Based on |
787 | | -patch by Philipp Hagemeister. |
788 | | - |
789 | | -.. |
790 | | -
|
791 | 812 | .. bpo: 26717 |
792 | 813 | .. date: 9596 |
793 | 814 | .. nonce: jngTdu |
@@ -937,17 +958,6 @@ Peter Inglesby. |
937 | 958 |
|
938 | 959 | .. |
939 | 960 |
|
940 | | -.. bpo: 26313 |
941 | | -.. date: 9581 |
942 | | -.. nonce: LjZAjy |
943 | | -.. original section: Library |
944 | | -.. section: Security |
945 | | -
|
946 | | -ssl.py _load_windows_store_certs fails if windows cert store is empty. Patch |
947 | | -by Baji. |
948 | | - |
949 | | -.. |
950 | | -
|
951 | 961 | .. bpo: 26569 |
952 | 962 | .. date: 9580 |
953 | 963 | .. nonce: EX8vF1 |
@@ -1136,16 +1146,6 @@ socket) when verify_request() returns false. Patch by Aviv Palivoda. |
1136 | 1146 |
|
1137 | 1147 | .. |
1138 | 1148 |
|
1139 | | -.. bpo: 25939 |
1140 | | -.. date: 9561 |
1141 | | -.. nonce: X49Fqd |
1142 | | -.. original section: Library |
1143 | | -.. section: Security |
1144 | | -
|
1145 | | -On Windows open the cert store readonly in ssl.enum_certificates. |
1146 | | - |
1147 | | -.. |
1148 | | -
|
1149 | 1149 | .. bpo: 25995 |
1150 | 1150 | .. date: 9560 |
1151 | 1151 | .. nonce: NfcimP |
@@ -2154,6 +2154,16 @@ Excludes venv from library when generating embeddable distro. |
2154 | 2154 |
|
2155 | 2155 | .. |
2156 | 2156 |
|
| 2157 | +.. bpo: 17500 |
| 2158 | +.. date: 9453 |
| 2159 | +.. nonce: QTZbRV |
| 2160 | +.. section: Windows |
| 2161 | +
|
| 2162 | +Remove unused and outdated icons. (See also: |
| 2163 | +https://github.com/python/pythondotorg/issues/945) |
| 2164 | + |
| 2165 | +.. |
| 2166 | +
|
2157 | 2167 | .. bpo: 26799 |
2158 | 2168 | .. date: 9457 |
2159 | 2169 | .. nonce: gK2VXX |
@@ -2191,13 +2201,3 @@ Teo. |
2191 | 2201 | .. section: Tools/Demos |
2192 | 2202 |
|
2193 | 2203 | Fix variable name typo in Argument Clinic. |
2194 | | - |
2195 | | -.. |
2196 | | -
|
2197 | | -.. bpo: 17500 |
2198 | | -.. date: 9453 |
2199 | | -.. nonce: QTZbRV |
2200 | | -.. section: Windows |
2201 | | -
|
2202 | | -Remove unused and outdated icons. (See also: |
2203 | | -https://github.com/python/pythondotorg/issues/945) |
0 commit comments