| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | Issue #27369: Don’t test error message detail that changed in Expat 2.2.03.2 | Martin Panter | 2016-07-14 | 1 | -0/+3 |
| | | |||||
| * | Issue #22758: Move NEWS entry to Library section | Martin Panter | 2016-07-14 | 1 | -3/+3 |
| | | |||||
| * | #22758: fix regression in handling of secure cookies. | R David Murray | 2016-07-10 | 1 | -0/+3 |
| | | | | | | This backports the fix from #16611, per discussion with the release manager. | ||||
| * | Issue #25940: Use self-signed.pythontest.net in SSL tests | Martin Panter | 2016-01-14 | 1 | -0/+7 |
| | | | | | | | | | | | | | | | | | | | | | This is instead of svn.python.org, whose certificate recently expired, and whose new certificate uses a different root certificate. The certificate used at the pythontest server was modifed to set the "basic constraints" CA flag. This flag seems to be required for test_get_ca_certs_ capath() to work (in Python 3.4+). Added the new self-signed certificate to capath with the following commands: cp Lib/test/{selfsigned_pythontestdotnet.pem,capath/} c_rehash -v Lib/test/capath/ c_rehash -v -old Lib/test/capath/ # Note the generated file names cp Lib/test/capath/{selfsigned_pythontestdotnet.pem,0e4015b9.0} mv Lib/test/capath/{selfsigned_pythontestdotnet.pem,ce7b8643.0} The new server responds with "No route to host" when connecting to port 444. | ||||
| * | add CVE and issue number | Benjamin Peterson | 2015-12-05 | 1 | -2/+3 |
| | | |||||
| * | allow square brackets in cookie values (closes #22931) | Benjamin Peterson | 2015-05-23 | 1 | -0/+5 |
| | | |||||
| * | properly handle malloc failure (closes #24044) | Benjamin Peterson | 2015-04-23 | 1 | -0/+3 |
| | | | | | Patch by Christian Heimes. | ||||
| * | remove RPM, since it's unused and unmaintained | Benjamin Peterson | 2015-02-18 | 3 | -424/+0 |
| | | |||||
| * | Issue #23055: Fixed a buffer overflow in PyUnicode_FromFormatV. Analysis | Serhiy Storchaka | 2015-01-27 | 1 | -0/+12 |
| | | | | | and fix by Guido Vranken. | ||||
| * | add some overflow checks before multiplying (closes #23165) | Benjamin Peterson | 2015-01-04 | 1 | -0/+3 |
| | | |||||
| * | add a default limit for the amount of data xmlrpclib.gzip_decode will return ↵ | Benjamin Peterson | 2014-12-06 | 1 | -0/+3 |
| | | | | | (closes #16043) | ||||
| * | Bump to 3.2.6v3.2.6 | Georg Brandl | 2014-10-12 | 1 | -1/+1 |
| | | |||||
| * | #16040: fix unlimited read from connection in nntplib. | Georg Brandl | 2014-10-12 | 1 | -0/+4 |
| | | |||||
| * | Bump to 3.2.6rc1 | Georg Brandl | 2014-10-04 | 2 | -2/+2 |
| | | |||||
| * | Fix unicode_aswidechar() for 4b unicode and 2b wchar_t (AIX). | Georg Brandl | 2014-10-01 | 1 | -0/+6 |
| | | |||||
| * | Issue #19855: uuid.getnode() on Unix now looks on the PATH for the | Georg Brandl | 2014-09-30 | 2 | -0/+15 |
| | | | | | | | | | | | | | | | executables used to find the mac address, with /sbin and /usr/sbin as fallbacks. Issue #11508: Fixed uuid.getnode() and uuid.uuid1() on environment with virtual interface. Original patch by Kent Frazier. Issue #18784: The uuid module no more attempts to load libc via ctypes.CDLL, if all necessary functions are already found in libuuid. Patch by Evgeny Sologubov. Issue #16102: Make uuid._netbios_getnode() work again on Python 3. | ||||
| * | Issue #20939: Use www.example.com instead of www.python.org to avoid test | Ned Deily | 2014-03-27 | 1 | -0/+7 |
| | | | | | failures when ssl is not present. | ||||
| * | Issue #16039: CVE-2013-1752: Change use of readline in imaplib module to limit | Georg Brandl | 2014-09-30 | 1 | -0/+3 |
| | | | | | line length. Patch by Emil Lind. | ||||
| * | Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all ↵ | Georg Brandl | 2014-09-17 | 1 | -0/+3 |
| | | | | | interfaces. | ||||
| * | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 2 | -0/+5 |
| | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
| * | Issue #22419: Limit the length of incoming HTTP request in wsgiref server to | Georg Brandl | 2014-09-30 | 2 | -0/+5 |
| | | | | | | 65536 bytes and send a 414 error code for higher lengths. Patch contributed by Devin Cook. | ||||
| * | Issue #22517: When a io.BufferedRWPair object is deallocated, clear its | Georg Brandl | 2014-09-30 | 1 | -0/+3 |
| | | | | | weakrefs. | ||||
| * | Issue #16041: CVE-2013-1752: poplib: Limit maximum line lengths to 2048 to | Georg Brandl | 2014-09-30 | 1 | -0/+4 |
| | | | | | | prevent readline() calls from consuming too much memory. Patch by Jyrki Pulliainen. | ||||
| * | Issue #16042: CVE-2013-1752: smtplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 1 | -0/+3 |
| | | | | | limiting the call to readline(). Original patch by Christian Heimes. | ||||
| * | Issue #16038: CVE-2013-1752: ftplib: Limit amount of data read by | Georg Brandl | 2014-09-30 | 1 | -0/+4 |
| | | | | | | limiting the call to readline(). Original patch by Michał Jastrzębski and Giampaolo Rodola. | ||||
| * | Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more than | Georg Brandl | 2014-09-30 | 1 | -1/+4 |
| | | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen. | ||||
| * | Issue #18709: Fix CVE-2013-4238. The SSL module now handles NULL bytes | Georg Brandl | 2014-09-30 | 1 | -0/+6 |
| | | | | | | | | inside subjectAltName correctly. Formerly the module has used OpenSSL's GENERAL_NAME_print() function to get the string represention of ASN.1 strings for ``rfc822Name`` (email), ``dNSName`` (DNS) and ``uniformResourceIdentifier`` (URI). | ||||
| * | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 2 | -0/+4 |
| | | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
| * | url unquote the path before checking if it refers to a CGI script (closes ↵ | Benjamin Peterson | 2014-06-15 | 1 | -0/+3 |
| | | | | | #21766) | ||||
| * | in scan_once, prevent the reading of arbitrary memory when passed a negative ↵ | Benjamin Peterson | 2014-04-14 | 2 | -0/+4 |
| | | | | | | | index Bug reported by Guido Vranken. | ||||
| * | remove directory mode check from makedirs (closes #21082) | Benjamin Peterson | 2014-04-01 | 1 | -0/+3 |
| | | |||||
| * | add Ian Beer | Benjamin Peterson | 2014-03-31 | 1 | -0/+1 |
| | | |||||
| * | complain when nbytes > buflen to fix possible buffer overflow (closes #20246) | Benjamin Peterson | 2014-01-14 | 2 | -0/+3 |
| | | |||||
| * | Issue #12226: HTTPS is now used by default when connecting to PyPI. | Antoine Pitrou | 2013-12-22 | 1 | -0/+2 |
| | | |||||
| * | Backout 7d399099334d. | Georg Brandl | 2013-11-04 | 1 | -3/+0 |
| | | |||||
| * | Update NEWS for 265d369ad3b9. | Jason R. Coombs | 2013-11-02 | 1 | -0/+3 |
| | | |||||
| * | merge 3.1 (#19435) | Benjamin Peterson | 2013-10-30 | 1 | -0/+2 |
| |\ | |||||
| | * | use the collapsed path in the run_cgi method (closes #19435) | Benjamin Peterson | 2013-10-30 | 1 | -0/+2 |
| | | | |||||
| * | | Merge #14984: On POSIX, enforce permissions when reading default .netrc. | R David Murray | 2013-09-18 | 1 | -0/+6 |
| |\ \ | |/ | |||||
| | * | #14984: On POSIX, enforce permissions when reading default .netrc. | R David Murray | 2013-09-18 | 1 | -0/+6 |
| | | | | | | | | | | | | | | | | | Initial patch by Bruno Piguet. This is implemented as if a useful .netrc file could exist without passwords, which is possible in the general case; but in fact our netrc implementation does not support it. Fixing that issue will be an enhancement. | ||||
| | * | Issue #16248: Disable code execution from the user's home directory by ↵ | Antoine Pitrou | 2012-12-09 | 1 | -0/+3 |
| | | | | | | | | | | | | | tkinter when the -E flag is passed to Python. Patch by Zachary Ware. | ||||
| | * | after 3.1.5 | Benjamin Peterson | 2012-04-11 | 1 | -0/+12 |
| | | | |||||
| | * | bump to 3.1.5 finalv3.1.5 | Benjamin Peterson | 2012-04-06 | 2 | -2/+2 |
| | | | |||||
| | * | merge headsv3.1.5rc2 | Benjamin Peterson | 2012-03-15 | 1 | -1/+1 |
| | |\ | |||||
| | | * | merge heads | Matthias Klose | 2012-03-14 | 1 | -1/+1 |
| | | |\ | |||||
| | | | * | - rename configure.in to configure.ac | Matthias Klose | 2012-03-14 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | | - change references from configure.in to configure.ac | ||||
| | | * | | move the Misc/NEWS entry to the right section. | Gregory P. Smith | 2012-03-14 | 1 | -3/+3 |
| | | | | | |||||
| | * | | | bump to 3.1.5rc2 | Benjamin Peterson | 2012-03-15 | 2 | -1/+6 |
| | | |/ | |/| | |||||
| * | | | Add a NEWS entry for b9b521efeba3. | Georg Brandl | 2013-09-14 | 1 | -0/+3 |
| | | | | |||||
| * | | | Add NEWS entry for c18c18774e24. | Georg Brandl | 2013-09-14 | 1 | -0/+11 |
| | | | | |||||
