Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | merge 3.2 (#22931) | Benjamin Peterson | 2015-05-23 | 1 | -0/+13 |
|\ | |||||
| * | allow square brackets in cookie values (closes #22931) | Benjamin Peterson | 2015-05-23 | 1 | -0/+14 |
| | | |||||
| * | Issue #23055: Fixed a buffer overflow in PyUnicode_FromFormatV. Analysis | Serhiy Storchaka | 2015-01-27 | 1 | -16/+129 |
| | | | | | | | | and fix by Guido Vranken. | ||||
* | | be more robust against the filters list changing under us (closes #24096) | Benjamin Peterson | 2015-05-03 | 1 | -0/+12 |
| | | |||||
* | | just sort the items tuple directly (closes #24094) | Benjamin Peterson | 2015-05-03 | 1 | -0/+19 |
| | | |||||
* | | Issues #23363, #23364, #23365, #23366: Fixed itertools overflow tests. | Serhiy Storchaka | 2015-02-02 | 1 | -7/+5 |
| | | | | | | | | Used PyMem_New to check overflow. | ||||
* | | reduce memory usage of test (closes #23369) | Benjamin Peterson | 2015-02-02 | 1 | -1/+2 |
| | | |||||
* | | check for overflows in permutations() and product() (closes #23363, closes ↵ | Benjamin Peterson | 2015-02-02 | 1 | -0/+12 |
| | | | | | | | | #23364) | ||||
* | | check for overflow in combinations_with_replacement (closes #23365) | Benjamin Peterson | 2015-02-02 | 1 | -1/+5 |
| | | |||||
* | | detect overflow in combinations (closes #23366) | Benjamin Peterson | 2015-02-02 | 1 | -0/+5 |
| | | |||||
* | | remove extra ws | Benjamin Peterson | 2015-02-01 | 1 | -1/+0 |
| | | |||||
* | | fix possible overflow in encode_basestring_ascii (closes #23369) | Benjamin Peterson | 2015-02-01 | 1 | -1/+8 |
| | | |||||
* | | Issue #23055: Fixed a buffer overflow in PyUnicode_FromFormatV. Analysis | Serhiy Storchaka | 2015-01-27 | 1 | -42/+119 |
| | | | | | | | | and fix by Guido Vranken. | ||||
* | | merge 3.2 (#16043) | Benjamin Peterson | 2014-12-06 | 1 | -1/+22 |
|\ \ | |/ | |||||
| * | add a default limit for the amount of data xmlrpclib.gzip_decode will return ↵ | Benjamin Peterson | 2014-12-06 | 1 | -1/+22 |
| | | | | | | | | (closes #16043) | ||||
* | | merge 3.2 | Benjamin Peterson | 2014-11-05 | 1 | -2/+2 |
|\ \ | |/ | |||||
| * | use pythontest.net for url fragment test | Benjamin Peterson | 2014-11-05 | 1 | -2/+2 |
| | | |||||
* | | merge 3.2 | Benjamin Peterson | 2014-11-03 | 1 | -3/+4 |
|\ \ | |/ | |||||
| * | move idna test domain to pythontest.net | Benjamin Peterson | 2014-11-03 | 1 | -3/+4 |
| | | |||||
| * | #16040: fix unlimited read from connection in nntplib. | Georg Brandl | 2014-10-12 | 1 | -0/+10 |
| | | |||||
| * | ref #19855: skip uuid test_find_mac on non-Posix as in later branches | Georg Brandl | 2014-10-01 | 1 | -2/+3 |
| | | |||||
| * | Issue #19855: uuid.getnode() on Unix now looks on the PATH for the | Georg Brandl | 2014-09-30 | 1 | -0/+21 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | executables used to find the mac address, with /sbin and /usr/sbin as fallbacks. Issue #11508: Fixed uuid.getnode() and uuid.uuid1() on environment with virtual interface. Original patch by Kent Frazier. Issue #18784: The uuid module no more attempts to load libc via ctypes.CDLL, if all necessary functions are already found in libuuid. Patch by Evgeny Sologubov. Issue #16102: Make uuid._netbios_getnode() work again on Python 3. | ||||
| * | Backport b533cc11d114 to fix intermittent test_urllibnet failures. | Georg Brandl | 2014-09-30 | 1 | -1/+1 |
| | | |||||
| * | Issue #20939: Use www.example.com instead of www.python.org to avoid test | Ned Deily | 2014-03-27 | 2 | -18/+18 |
| | | | | | | | | failures when ssl is not present. | ||||
| * | Issue #16039: CVE-2013-1752: Change use of readline in imaplib module to limit | Georg Brandl | 2014-09-30 | 1 | -0/+11 |
| | | | | | | | | line length. Patch by Emil Lind. | ||||
| * | Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all ↵ | Georg Brandl | 2014-09-17 | 1 | -0/+2 |
| | | | | | | | | interfaces. | ||||
| * | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 1 | -0/+9 |
| | | | | | | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
| * | Issue #22419: Limit the length of incoming HTTP request in wsgiref server to | Georg Brandl | 2014-09-30 | 1 | -0/+5 |
| | | | | | | | | | | 65536 bytes and send a 414 error code for higher lengths. Patch contributed by Devin Cook. | ||||
| * | Issue #22517: When a io.BufferedRWPair object is deallocated, clear its | Georg Brandl | 2014-09-30 | 1 | -0/+6 |
| | | | | | | | | weakrefs. | ||||
| * | Issue #16041: CVE-2013-1752: poplib: Limit maximum line lengths to 2048 to | Georg Brandl | 2014-09-30 | 1 | -1/+5 |
| | | | | | | | | | | prevent readline() calls from consuming too much memory. Patch by Jyrki Pulliainen. | ||||
| * | Issue #16042: CVE-2013-1752: smtplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 2 | -3/+36 |
| | | | | | | | | limiting the call to readline(). Original patch by Christian Heimes. | ||||
| * | Issue #16038: CVE-2013-1752: ftplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 1 | -1/+21 |
| | | | | | | | | | | limiting the call to readline(). Original patch by Michał Jastrzębski and Giampaolo Rodola. | ||||
| * | Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more than | Georg Brandl | 2014-09-30 | 1 | -0/+9 |
| | | | | | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen. | ||||
| * | Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytes | Georg Brandl | 2014-09-30 | 2 | -0/+119 |
| | | | | | | | | | | | | | | inside subjectAltName correctly. Formerly the module has used OpenSSL's GENERAL_NAME_print() function to get the string represention of ASN.1 strings for ``rfc822Name`` (email), ``dNSName`` (DNS) and ``uniformResourceIdentifier`` (URI). | ||||
* | | test is cpython only | Benjamin Peterson | 2014-10-15 | 1 | -0/+1 |
| | | |||||
* | | fix integer overflow in unicode case operations (closes #22643) | Benjamin Peterson | 2014-10-15 | 1 | -0/+5 |
| | | |||||
* | | clear BufferedRWPair weakrefs on deallocation (closes #22517) | Benjamin Peterson | 2014-09-30 | 1 | -0/+6 |
| | | |||||
* | | Issue #22419: Limit the length of incoming HTTP request in wsgiref server to ↵ | Senthil Kumaran | 2014-09-17 | 1 | -0/+5 |
| | | | | | | | | 65536 bytes. | ||||
* | | Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all ↵ | Senthil Kumaran | 2014-09-17 | 1 | -0/+2 |
| | | | | | | | | interfaces. | ||||
* | | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 1 | -0/+9 |
| | | | | | | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
* | | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 1 | -0/+16 |
|\ \ | |/ | | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
| * | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 1 | -0/+16 |
| | | | | | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
* | | merge 3.2 | Benjamin Peterson | 2014-06-17 | 1 | -1/+1 |
|\ \ | |/ | |||||
| * | expect the correct platform-dependent linesep | Benjamin Peterson | 2014-06-17 | 1 | -1/+1 |
| | | |||||
* | | merge 3.2 (#21766) | Benjamin Peterson | 2014-06-15 | 1 | -0/+5 |
|\ \ | |/ | |||||
| * | url unquote the path before checking if it refers to a CGI script (closes ↵ | Benjamin Peterson | 2014-06-15 | 1 | -0/+5 |
| | | | | | | | | #21766) | ||||
* | | merge 3.2 | Benjamin Peterson | 2014-04-14 | 1 | -0/+4 |
|\ \ | |/ | |||||
| * | in scan_once, prevent the reading of arbitrary memory when passed a negative ↵ | Benjamin Peterson | 2014-04-14 | 1 | -0/+4 |
| | | | | | | | | | | | | index Bug reported by Guido Vranken. | ||||
* | | merge 3.2 (#21082) | Benjamin Peterson | 2014-04-01 | 1 | -4/+3 |
|\ \ | |/ | |||||
| * | remove directory mode check from makedirs (closes #21082) | Benjamin Peterson | 2014-04-01 | 1 | -4/+3 |
| | |