Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | add a default limit for the amount of data xmlrpclib.gzip_decode will return ↵ | Benjamin Peterson | 2014-12-06 | 1 | -1/+22 |
| | | | | (closes #16043) | ||||
* | use pythontest.net for url fragment test | Benjamin Peterson | 2014-11-05 | 1 | -2/+2 |
| | |||||
* | move idna test domain to pythontest.net | Benjamin Peterson | 2014-11-03 | 1 | -3/+4 |
| | |||||
* | #16040: fix unlimited read from connection in nntplib. | Georg Brandl | 2014-10-12 | 1 | -0/+10 |
| | |||||
* | ref #19855: skip uuid test_find_mac on non-Posix as in later branches | Georg Brandl | 2014-10-01 | 1 | -2/+3 |
| | |||||
* | Issue #19855: uuid.getnode() on Unix now looks on the PATH for the | Georg Brandl | 2014-09-30 | 1 | -0/+21 |
| | | | | | | | | | | | | | | executables used to find the mac address, with /sbin and /usr/sbin as fallbacks. Issue #11508: Fixed uuid.getnode() and uuid.uuid1() on environment with virtual interface. Original patch by Kent Frazier. Issue #18784: The uuid module no more attempts to load libc via ctypes.CDLL, if all necessary functions are already found in libuuid. Patch by Evgeny Sologubov. Issue #16102: Make uuid._netbios_getnode() work again on Python 3. | ||||
* | Backport b533cc11d114 to fix intermittent test_urllibnet failures. | Georg Brandl | 2014-09-30 | 1 | -1/+1 |
| | |||||
* | Issue #20939: Use www.example.com instead of www.python.org to avoid test | Ned Deily | 2014-03-27 | 2 | -18/+18 |
| | | | | failures when ssl is not present. | ||||
* | Issue #16039: CVE-2013-1752: Change use of readline in imaplib module to limit | Georg Brandl | 2014-09-30 | 1 | -0/+11 |
| | | | | line length. Patch by Emil Lind. | ||||
* | Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all ↵ | Georg Brandl | 2014-09-17 | 1 | -0/+2 |
| | | | | interfaces. | ||||
* | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 1 | -0/+9 |
| | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
* | Issue #22419: Limit the length of incoming HTTP request in wsgiref server to | Georg Brandl | 2014-09-30 | 1 | -0/+5 |
| | | | | | 65536 bytes and send a 414 error code for higher lengths. Patch contributed by Devin Cook. | ||||
* | Issue #22517: When a io.BufferedRWPair object is deallocated, clear its | Georg Brandl | 2014-09-30 | 1 | -0/+6 |
| | | | | weakrefs. | ||||
* | Issue #16041: CVE-2013-1752: poplib: Limit maximum line lengths to 2048 to | Georg Brandl | 2014-09-30 | 1 | -1/+5 |
| | | | | | prevent readline() calls from consuming too much memory. Patch by Jyrki Pulliainen. | ||||
* | Issue #16042: CVE-2013-1752: smtplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 2 | -3/+36 |
| | | | | limiting the call to readline(). Original patch by Christian Heimes. | ||||
* | Issue #16038: CVE-2013-1752: ftplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 1 | -1/+21 |
| | | | | | limiting the call to readline(). Original patch by Michał Jastrzębski and Giampaolo Rodola. | ||||
* | Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more than | Georg Brandl | 2014-09-30 | 1 | -0/+9 |
| | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen. | ||||
* | Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytes | Georg Brandl | 2014-09-30 | 2 | -0/+119 |
| | | | | | | | inside subjectAltName correctly. Formerly the module has used OpenSSL's GENERAL_NAME_print() function to get the string represention of ASN.1 strings for ``rfc822Name`` (email), ``dNSName`` (DNS) and ``uniformResourceIdentifier`` (URI). | ||||
* | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 1 | -0/+16 |
| | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
* | expect the correct platform-dependent linesep | Benjamin Peterson | 2014-06-17 | 1 | -1/+1 |
| | |||||
* | url unquote the path before checking if it refers to a CGI script (closes ↵ | Benjamin Peterson | 2014-06-15 | 1 | -0/+5 |
| | | | | #21766) | ||||
* | in scan_once, prevent the reading of arbitrary memory when passed a negative ↵ | Benjamin Peterson | 2014-04-14 | 1 | -0/+4 |
| | | | | | | index Bug reported by Guido Vranken. | ||||
* | remove directory mode check from makedirs (closes #21082) | Benjamin Peterson | 2014-04-01 | 1 | -4/+3 |
| | |||||
* | use https docs url (#21115) | Benjamin Peterson | 2014-03-31 | 1 | -2/+2 |
| | |||||
* | use ssl.PROTOCOL_SSLv23 for maximum compatibility (closes #20896) | Benjamin Peterson | 2014-03-12 | 1 | -3/+8 |
| | |||||
* | Issue #20246: Fix test failures on FreeBSD. Patch by Ryan Smith-Roberts. | Stefan Krah | 2014-01-21 | 1 | -1/+1 |
| | |||||
* | update logo url (#20695) | Benjamin Peterson | 2014-02-20 | 1 | -1/+1 |
| | |||||
* | open retrieved file in binary mode, since it's now compressed | Benjamin Peterson | 2014-02-20 | 1 | -3/+3 |
| | |||||
* | complain when nbytes > buflen to fix possible buffer overflow (closes #20246) | Benjamin Peterson | 2014-01-14 | 1 | -0/+8 |
| | |||||
* | merge 3.1 (#19435) | Benjamin Peterson | 2013-10-30 | 1 | -0/+12 |
|\ | |||||
| * | use the collapsed path in the run_cgi method (closes #19435) | Benjamin Peterson | 2013-10-30 | 1 | -0/+10 |
| | | |||||
* | | Merge #14984: On POSIX, enforce permissions when reading default .netrc. | R David Murray | 2013-09-18 | 1 | -3/+23 |
|\ \ | |/ | |||||
| * | #14984: On POSIX, enforce permissions when reading default .netrc. | R David Murray | 2013-09-18 | 1 | -3/+23 |
| | | | | | | | | | | | | | | | | Initial patch by Bruno Piguet. This is implemented as if a useful .netrc file could exist without passwords, which is possible in the general case; but in fact our netrc implementation does not support it. Fixing that issue will be an enhancement. | ||||
| * | Remove setting hash seed to regrtest's random seed and re-execv()ing: this ↵ | Georg Brandl | 2012-02-20 | 1 | -5/+0 |
| | | | | | | | | doesn't preserve Python flags and fails from a temp directory. | ||||
| * | Fix dbm_gnu test relying on set order. | Georg Brandl | 2012-02-20 | 1 | -1/+1 |
| | | |||||
* | | Issue #17980: Fix possible abuse of ssl.match_hostname() for denial of ↵ | Antoine Pitrou | 2013-05-18 | 1 | -0/+11 |
| | | | | | | | | service using certificates with many wildcards (CVE-2013-2099). | ||||
* | | Issue #17915: Fix interoperability of xml.sax with file objects returned by | Georg Brandl | 2013-05-12 | 1 | -0/+31 |
| | | | | | | | | codecs.open(). | ||||
* | | Issue #1159051: Back out a fix for handling corrupted gzip files that | Georg Brandl | 2013-05-12 | 2 | -31/+0 |
| | | | | | | | | broke backwards compatibility. | ||||
* | | Issue #17843: Remove bz2 test data that triggers antivirus warnings. | Georg Brandl | 2013-05-12 | 2 | -7/+6 |
| | | |||||
* | | Issue #15535: Fix pickling of named tuples. | Georg Brandl | 2013-05-12 | 1 | -0/+1 |
| | | |||||
* | | Close #17666: Fix reading gzip files with an extra field. | Serhiy Storchaka | 2013-04-08 | 1 | -0/+7 |
| | | |||||
* | | Clean up references to threads in test_queue. | Ezio Melotti | 2013-03-23 | 1 | -1/+4 |
| | | |||||
* | | Fixes issue #17488: Change the subprocess.Popen bufsize parameter default value | Gregory P. Smith | 2013-03-23 | 1 | -0/+22 |
| | | | | | | | | | | | | from unbuffered (0) to buffering (-1) to match the behavior existing code expects and match the behavior of the subprocess module in Python 2 to avoid introducing hard to track down bugs. | ||||
* | | Issue #17521: Corrected non-enabling of logger following two calls to ↵ | Vinay Sajip | 2013-03-23 | 1 | -2/+32 |
| | | | | | | | | fileConfig(). | ||||
* | | Issue #17508: Handled out-of-order handler configuration correctly. | Vinay Sajip | 2013-03-22 | 1 | -2/+36 |
| | | |||||
* | | #5712: Preemptively fix some other possible timing issues. | R David Murray | 2013-03-21 | 1 | -3/+3 |
| | | |||||
* | | #5713: fix timing issue in smtplib tests. | R David Murray | 2013-03-21 | 1 | -0/+3 |
| | | |||||
* | | #5713: Handle 421 error codes during sendmail by closing the socket. | R David Murray | 2013-03-21 | 1 | -1/+64 |
| | | | | | | | | | | | | | | | | | | This is a partial fix to the issue of servers disconnecting unexpectedly; in this case the 421 says they are disconnecting, so we close the socket and return the 421 in the appropriate error context. Original patch by Mark Sapiro, updated by Kushal Das, with additional tests by me. | ||||
* | | #17493: re-enable a test on Windows. Patch by Zachary Ware. | Ezio Melotti | 2013-03-20 | 1 | -11/+9 |
| | | |||||
* | | #17471 - Increasing the urllib.error test coverage. Bringing it to 100%. ↵ | Senthil Kumaran | 2013-03-19 | 1 | -1/+9 |
| | | | | | | | | Based on patch contributed by Daniel Wozniak |