summaryrefslogtreecommitdiffstats
path: root/Misc/NEWS
Commit message (Expand)AuthorAgeFilesLines
* fix possible integer overflow in binascii.b2a_qp (closes #27760)Benjamin Peterson2016-08-141-0/+2
* check for overflow in join_append_data (closes #27758)Benjamin Peterson2016-08-141-0/+3
* Prevent HTTPoxy attack (CVE-2016-1000110)Senthil Kumaran2016-07-311-0/+4
* Issue #27369: Merge test_pyexpat from 3.2 into 3.3Martin Panter2016-07-141-0/+3
|\
| * Issue #27369: Don’t test error message detail that changed in Expat 2.2.03.2Martin Panter2016-07-141-0/+3
| * Issue #22758: Move NEWS entry to Library sectionMartin Panter2016-07-141-3/+3
| * #22758: fix regression in handling of secure cookies.R David Murray2016-07-101-0/+3
* | Issue #25709: Fixed problem with in-place string concatenation and utf-8 cache.Serhiy Storchaka2015-12-021-0/+5
* | Issue #25940: Merge self-signed.pythontest.net testing from 3.2 into 3.3Martin Panter2016-01-141-0/+7
|\ \ | |/
| * Issue #25940: Use self-signed.pythontest.net in SSL testsMartin Panter2016-01-141-0/+7
* | fix reorderingBenjamin Peterson2015-12-051-4/+4
* | merge 3.2Benjamin Peterson2015-12-051-3/+4
|\ \ | |/
| * add CVE and issue numberBenjamin Peterson2015-12-051-2/+3
* | protect against mutation of the dict during insertion (closes #24407)Benjamin Peterson2015-07-051-0/+2
* | add issue numberBenjamin Peterson2015-06-271-1/+1
* | use safe allocation and reallocation macrosBenjamin Peterson2015-06-271-0/+2
* | merge 3.2 (#22931)Benjamin Peterson2015-05-231-0/+2
|\ \ | |/
| * allow square brackets in cookie values (closes #22931)Benjamin Peterson2015-05-231-0/+5
* | be more robust against the filters list changing under us (closes #24096)Benjamin Peterson2015-05-031-0/+3
* | just sort the items tuple directly (closes #24094)Benjamin Peterson2015-05-031-0/+3
* | merge 3.2 (#24044)Benjamin Peterson2015-04-231-0/+3
|\ \ | |/
| * properly handle malloc failure (closes #24044)Benjamin Peterson2015-04-231-0/+3
| * Issue #23055: Fixed a buffer overflow in PyUnicode_FromFormatV. AnalysisSerhiy Storchaka2015-01-271-0/+12
* | Issue #23998: PyImport_ReInitLock() now checks for lock allocation errorChristian Heimes2015-04-191-0/+5
* | fix possible overflow bugs in unicodedata (closes #23367)Benjamin Peterson2015-03-021-0/+2
* | add overflow checking (closes #23361)Benjamin Peterson2015-02-101-0/+2
* | check for overflows in permutations() and product() (closes #23363, closes #2...Benjamin Peterson2015-02-021-0/+4
* | check for overflow in combinations_with_replacement (closes #23365)Benjamin Peterson2015-02-021-0/+3
* | detect overflow in combinations (closes #23366)Benjamin Peterson2015-02-021-0/+2
* | fix possible overflow in encode_basestring_ascii (closes #23369)Benjamin Peterson2015-02-011-0/+6
* | Issue #23055: Fixed a buffer overflow in PyUnicode_FromFormatV. AnalysisSerhiy Storchaka2015-01-271-0/+12
* | merge 3.2 (closes #23165)Benjamin Peterson2015-01-041-0/+3
|\ \ | |/
| * add some overflow checks before multiplying (closes #23165)Benjamin Peterson2015-01-041-0/+3
* | merge 3.2 (#16043)Benjamin Peterson2014-12-061-0/+3
|\ \ | |/
| * add a default limit for the amount of data xmlrpclib.gzip_decode will return ...Benjamin Peterson2014-12-061-0/+3
| * #16040: fix unlimited read from connection in nntplib.Georg Brandl2014-10-121-0/+4
| * Bump to 3.2.6rc1Georg Brandl2014-10-041-1/+1
| * Fix unicode_aswidechar() for 4b unicode and 2b wchar_t (AIX).Georg Brandl2014-10-011-0/+6
| * Issue #19855: uuid.getnode() on Unix now looks on the PATH for theGeorg Brandl2014-09-301-0/+13
| * Issue #20939: Use www.example.com instead of www.python.org to avoid testNed Deily2014-03-271-0/+7
| * Issue #16039: CVE-2013-1752: Change use of readline in imaplib module to limitGeorg Brandl2014-09-301-0/+3
| * Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all i...Georg Brandl2014-09-171-0/+3
| * Lax cookie parsing in http.cookies could be a security issue when combinedAntoine Pitrou2014-09-161-0/+4
| * Issue #22419: Limit the length of incoming HTTP request in wsgiref server toGeorg Brandl2014-09-301-0/+4
| * Issue #22517: When a io.BufferedRWPair object is deallocated, clear itsGeorg Brandl2014-09-301-0/+3
| * Issue #16041: CVE-2013-1752: poplib: Limit maximum line lengths to 2048 toGeorg Brandl2014-09-301-0/+4
| * Issue #16042: CVE-2013-1752: smtplib: Limit amount of data read byGeorg Brandl2014-09-301-0/+3
| * Issue #16038: CVE-2013-1752: ftplib: Limit amount of data read byGeorg Brandl2014-09-301-0/+4
| * Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more thanGeorg Brandl2014-09-301-1/+4
| * Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytesGeorg Brandl2014-09-301-0/+6