cpython/Misc/NEWS.d/next/Security
Christian Heimes cb5778f00c bpo-34623: Use XML_SetHashSalt in _elementtree (GH-9146)
The C accelerated _elementtree module now initializes hash randomization
salt from _Py_HashSecret instead of libexpat's default CPRNG.

Signed-off-by: Christian Heimes <christian@python.org>



https://bugs.python.org/issue34623
2018-09-18 05:38:58 -07:00
..
2017-08-06-14-43-45.bpo-28414.mzZ6vD.rst [bpo-28414] Make all hostnames in SSL module IDN A-labels (GH-5128) 2018-02-23 17:35:08 -08:00
2018-03-02-10-24-52.bpo-32981.O_qDyj.rst bpo-32981: Fix catastrophic backtracking vulns (#5955) 2018-03-03 21:33:32 -08:00
2018-03-05-10-09-51.bpo-33001.elj4Aa.rst bpo-33001: Prevent buffer overrun in os.symlink (GH-5989) 2018-03-05 14:26:08 -08:00
2018-03-25-12-05-43.bpo-33136.TzSN4x.rst bpo-33136: Harden ssl module against CVE-2018-8970 (GH-6229) 2018-03-25 12:36:13 +02:00
2018-05-28-08-55-30.bpo-32533.IzwkBI.rst bpo-32533: Fixed thread-safety of error handling in _ssl. (GH-7158) 2018-09-17 11:34:47 -07:00
2018-06-26-19-35-33.bpo-33871.S4HR9n.rst bpo-33871: Fix os.sendfile(), os.writev(), os.readv(), etc. (GH-7931) 2018-07-31 10:24:54 +03:00
2018-08-15-12-12-47.bpo-34405.qbHTH_.rst bpo-34405: Updated to OpenSSL 1.1.0i for Windows builds. (GH-8775) 2018-08-15 13:29:24 -07:00
2018-09-10-16-05-39.bpo-34623.Ua9jMv.rst bpo-34623: Use XML_SetHashSalt in _elementtree (GH-9146) 2018-09-18 05:38:58 -07:00
README.rst Link to blurb on PyPI in the NEWS.d READMEs. (#3323) 2017-09-05 10:38:05 -07:00

README.rst

Put news entry `blurb`_ files for the *Security* section in this directory.

.. _blurb: https://pypi.org/project/blurb/