From 41577a6efeb8d2e65bde0d9a365bee9b012f0e1c76a127f59fad225bbef7da0b Mon Sep 17 00:00:00 2001 From: Matej Cepl Date: Mon, 2 Dec 2024 22:50:54 +0000 Subject: [PATCH] - Fix changelog (renamed from CVE-2024-8088-zipfile-Path-sanitization.patch) - CVE-2024-6232-ReDOS-backtrack-tarfile.patch - CVE-2024-7592-quad-complex-cookies.patch * CVE-2024-0397-memrace_ssl.SSLContext_cert_store.patch - Remove upstreamed patches: - CVE-2024-0450-zipfile-avoid-quoted-overlap-zipbomb.patch OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python311?expand=0&rev=151 --- python311.changes | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/python311.changes b/python311.changes index 97d8e4b..6d769f0 100644 --- a/python311.changes +++ b/python311.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Mon Dec 2 22:50:07 UTC 2024 - Matej Cepl + +- Fix changelog + ------------------------------------------------------------------- Mon Nov 11 12:43:40 UTC 2024 - Daniel Garcia @@ -99,6 +104,9 @@ Mon Sep 9 16:53:07 UTC 2024 - Matej Cepl - CVE-2024-4032-private-IP-addrs.patch - CVE-2024-6923-email-hdr-inject.patch - CVE-2024-8088-inf-loop-zipfile_Path.patch + (renamed from CVE-2024-8088-zipfile-Path-sanitization.patch) + - CVE-2024-6232-ReDOS-backtrack-tarfile.patch + - CVE-2024-7592-quad-complex-cookies.patch ------------------------------------------------------------------- Mon Sep 2 09:44:26 UTC 2024 - Matej Cepl @@ -185,6 +193,7 @@ Mon Apr 8 05:44:04 UTC 2024 - Daniel Garcia - Remove not needed upstream patches: * libexpat260.patch * CVE-2023-6597-TempDir-cleaning-symlink.patch, bsc#1219666 + * CVE-2024-0397-memrace_ssl.SSLContext_cert_store.patch - Update to 3.11.9: * Security @@ -737,7 +746,8 @@ Thu Feb 8 07:27:40 UTC 2024 - Daniel Garcia METH_FASTCALL | METH_KEYWORDS calling convention. Only the positional parameter count was checked; any keyword argument passed would be silently accepted. - +- Remove upstreamed patches: + - CVE-2024-0450-zipfile-avoid-quoted-overlap-zipbomb.patch - Refresh all patches: - CVE-2023-27043-email-parsing-errors.patch - F00251-change-user-install-location.patch