cpython/Misc/NEWS.d/next/Security/2022-04-27-18-25-30.gh-issu...

5 lines
245 B
ReStructuredText

The deprecated mailcap module now refuses to inject unsafe text (filenames,
MIME types, parameters) into shell commands. Instead of using such text, it
will warn and act as if a match was not found (or for test commands, as if
the test failed).