CVE-2016-5699 httplib header injection (bsc#985348)

(this one is actually fixed since 2.7.10)

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python?expand=0&rev=195
This commit is contained in:
Jan Matejek 2016-07-01 13:15:24 +00:00 committed by Git OBS Bridge
parent 95238b7fc9
commit 3d29b362e3

View File

@ -6,6 +6,8 @@ Thu Jun 30 09:23:05 UTC 2016 - jmatejek@suse.com
* fixes multiple security issues: * fixes multiple security issues:
CVE-2016-0772 TLS stripping attack on smtplib (bsc#984751) CVE-2016-0772 TLS stripping attack on smtplib (bsc#984751)
CVE-2016-5636 zipimporter heap overflow (bsc#985177) CVE-2016-5636 zipimporter heap overflow (bsc#985177)
CVE-2016-5699 httplib header injection (bsc#985348)
(this one is actually fixed since 2.7.10)
- removed upstreamed python-2.7.7-mhlib-linkcount.patch - removed upstreamed python-2.7.7-mhlib-linkcount.patch
- refreshed multilib patch - refreshed multilib patch
- python-2.7.12-makeopcode.patch - run newly-built python interpreter - python-2.7.12-makeopcode.patch - run newly-built python interpreter