summaryrefslogtreecommitdiffstats
path: root/Misc
diff options
context:
space:
mode:
authorBenjamin Peterson <benjamin@python.org>2012-03-15 18:57:27 (GMT)
committerBenjamin Peterson <benjamin@python.org>2012-03-15 18:57:27 (GMT)
commitba98788bc545232a0e1b9458179253cf120176f6 (patch)
treec51180f1ade157142291bf77cad2515ec4c282a2 /Misc
parent273cd1812a7c8646b52aa3afee1c5db5a0e539d6 (diff)
downloadcpython-ba98788bc545232a0e1b9458179253cf120176f6.zip
cpython-ba98788bc545232a0e1b9458179253cf120176f6.tar.gz
cpython-ba98788bc545232a0e1b9458179253cf120176f6.tar.bz2
bump to 3.1.5rc2
Diffstat (limited to 'Misc')
-rw-r--r--Misc/NEWS5
-rw-r--r--Misc/RPM/python-3.1.spec2
2 files changed, 6 insertions, 1 deletions
diff --git a/Misc/NEWS b/Misc/NEWS
index 07b981c..935b067 100644
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -18,6 +18,11 @@ Core and Builtins
Library
-------
+- Issue #14234: CVE-2012-0876: Randomize hashes of xml attributes in the hash
+ table internal to the pyexpat module's copy of the expat library to avoid a
+ denial of service due to hash collisions. Patch by David Malcolm with some
+ modifications by the expat project.
+
- Issue #14001: CVE-2012-0845: xmlrpc: Fix an endless loop in
SimpleXMLRPCServer upon malformed POST request.
diff --git a/Misc/RPM/python-3.1.spec b/Misc/RPM/python-3.1.spec
index c89c1da..235da2d 100644
--- a/Misc/RPM/python-3.1.spec
+++ b/Misc/RPM/python-3.1.spec
@@ -34,7 +34,7 @@
%define name python
#--start constants--
-%define version 3.1.5rc1
+%define version 3.1.5rc2
%define libvers 3.1
#--end constants--
%define release 1pydotorg