From 891e0342dacf409dc2edf1e7718f744cd89d547c0cb70d241b2426c9ea8e9c79 Mon Sep 17 00:00:00 2001 From: Matej Cepl Date: Fri, 29 Oct 2021 21:16:59 +0000 Subject: [PATCH] * bsc#1185768 (CVE-2021-42771) The internal locale-data loading functions now validate the name of the locale file to be loaded and only allow files within Babel's data directory. OBS-URL: https://build.opensuse.org/package/show/devel:languages:python/python-Babel?expand=0&rev=63 --- python-Babel.changes | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/python-Babel.changes b/python-Babel.changes index 4255aa3..3fc7eff 100644 --- a/python-Babel.changes +++ b/python-Babel.changes @@ -12,8 +12,9 @@ Thu Sep 30 15:35:45 UTC 2021 - Stefan Schubert Tue May 11 21:40:39 UTC 2021 - Dirk Müller - update to 2.9.1: - * The internal locale-data loading functions now validate the name of the - locale file to be loaded and only allow files within Babel's data directory. + * bsc#1185768 (CVE-2021-42771) The internal locale-data loading + functions now validate the name of the locale file to be + loaded and only allow files within Babel's data directory. ------------------------------------------------------------------- Fri Mar 5 10:31:45 UTC 2021 - Markéta Machová