NEWS: tag security related changes with [Security] prefix

Issue #27404.
This commit is contained in:
Victor Stinner 2016-07-28 17:06:25 +02:00
parent 3e5b1d3cf5
commit 4a865a35cd
1 changed files with 9 additions and 9 deletions

View File

@ -86,14 +86,14 @@ Library
when exiting, let the new chained one through. This avoids the PEP 479 when exiting, let the new chained one through. This avoids the PEP 479
bug described in issue25782. bug described in issue25782.
- Issue #27278: Fix os.urandom() implementation using getrandom() on Linux. - [Security] Issue #27278: Fix os.urandom() implementation using getrandom() on Linux.
Truncate size to INT_MAX and loop until we collected enough random bytes, Truncate size to INT_MAX and loop until we collected enough random bytes,
instead of casting a directly Py_ssize_t to int. instead of casting a directly Py_ssize_t to int.
- Issue #26386: Fixed ttk.TreeView selection operations with item id's - Issue #26386: Fixed ttk.TreeView selection operations with item id's
containing spaces. containing spaces.
- Issue #22636: Avoid shell injection problems with - [Security] Issue #22636: Avoid shell injection problems with
ctypes.util.find_library(). ctypes.util.find_library().
- Issue #16182: Fix various functions in the "readline" module to use the - Issue #16182: Fix various functions in the "readline" module to use the
@ -309,10 +309,10 @@ Core and Builtins
Library Library
------- -------
- Issue #26556: Update expat to 2.1.1, fixes CVE-2015-1283. - [Security] Issue #26556: Update expat to 2.1.1, fixes CVE-2015-1283.
- Fix TLS stripping vulnerability in smtplib, CVE-2016-0772. Reported by Team - [Security] Fix TLS stripping vulnerability in smtplib, CVE-2016-0772.
Oststrom Reported by Team Oststrom
- Issue #21386: Implement missing IPv4Address.is_global property. It was - Issue #21386: Implement missing IPv4Address.is_global property. It was
documented since 07a5610bae9d. Initial patch by Roger Luethi. documented since 07a5610bae9d. Initial patch by Roger Luethi.
@ -336,7 +336,7 @@ Library
- Issue #21313: Fix the "platform" module to tolerate when sys.version - Issue #21313: Fix the "platform" module to tolerate when sys.version
contains truncated build information. contains truncated build information.
- Issue #26839: On Linux, :func:`os.urandom` now calls ``getrandom()`` with - [Security] Issue #26839: On Linux, :func:`os.urandom` now calls ``getrandom()`` with
``GRND_NONBLOCK`` to fall back on reading ``/dev/urandom`` if the urandom ``GRND_NONBLOCK`` to fall back on reading ``/dev/urandom`` if the urandom
entropy pool is not initialized yet. Patch written by Colm Buckley. entropy pool is not initialized yet. Patch written by Colm Buckley.
@ -444,7 +444,7 @@ Library
- Issue #24838: tarfile's ustar and gnu formats now correctly calculate name - Issue #24838: tarfile's ustar and gnu formats now correctly calculate name
and link field limits for multibyte character encodings like utf-8. and link field limits for multibyte character encodings like utf-8.
- Issue #26657: Fix directory traversal vulnerability with http.server on - [Security] Issue #26657: Fix directory traversal vulnerability with http.server on
Windows. This fixes a regression that was introduced in 3.3.4rc1 and Windows. This fixes a regression that was introduced in 3.3.4rc1 and
3.4.0rc1. Based on patch by Philipp Hagemeister. 3.4.0rc1. Based on patch by Philipp Hagemeister.
@ -493,7 +493,7 @@ Library
- Issue #26560: Avoid potential ValueError in BaseHandler.start_response. - Issue #26560: Avoid potential ValueError in BaseHandler.start_response.
Initial patch by Peter Inglesby. Initial patch by Peter Inglesby.
- Issue #26313: ssl.py _load_windows_store_certs fails if windows cert store - [Security] Issue #26313: ssl.py _load_windows_store_certs fails if windows cert store
is empty. Patch by Baji. is empty. Patch by Baji.
- Issue #26569: Fix :func:`pyclbr.readmodule` and :func:`pyclbr.readmodule_ex` - Issue #26569: Fix :func:`pyclbr.readmodule` and :func:`pyclbr.readmodule_ex`
@ -555,7 +555,7 @@ Library
the connected socket) when verify_request() returns false. Patch by Aviv the connected socket) when verify_request() returns false. Patch by Aviv
Palivoda. Palivoda.
- Issue #25939: On Windows open the cert store readonly in ssl.enum_certificates. - [Security] Issue #25939: On Windows open the cert store readonly in ssl.enum_certificates.
- Issue #25995: os.walk() no longer uses FDs proportional to the tree depth. - Issue #25995: os.walk() no longer uses FDs proportional to the tree depth.