- Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst

case quadratic complexity when processing certain crafted
  malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705).

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python39?expand=0&rev=238
This commit is contained in:
2025-07-02 16:10:52 +00:00
committed by Git OBS Bridge
commit 9f343d4b19
58 changed files with 12780 additions and 0 deletions

View File

@@ -0,0 +1,11 @@
--- a/Lib/distutils/util.py
+++ b/Lib/distutils/util.py
@@ -433,7 +433,7 @@ byte_compile(files, optimize=%r, force=%
else:
from py_compile import compile
- for file in py_files:
+ for file in sorted(py_files):
if file[-3:] != ".py":
# This lets us be lazy and not filter filenames in
# the "install_lib" command.