forked from pool/python-waitress
		
	- Update to 3.0.1 (bsc#1232554, CVE-2024-49769):
* Fix a bug that would lead to Waitress busy looping on select()
      on a half-open socket due to a race condition that existed when
      creating a new HTTPChannel. See
      https://github.com/Pylons/waitress/pull/435,
      https://github.com/Pylons/waitress/issues/418 and
      https://github.com/Pylons/waitress/security/advisories/GHSA-3f84-rpwh-47g6
    * No longer strip the header values before passing them to the
      WSGI environ. See https://github.com/Pylons/waitress/pull/434
      and https://github.com/Pylons/waitress/issues/432
    * Fix a race condition in Waitress when
      `channel_request_lookahead` is enabled that could lead to HTTP
      request smuggling.
    * See https://github.com/Pylons/waitress/security/advisories/GHSA-9298-4cf8-g4wj
OBS-URL: https://build.opensuse.org/package/show/devel:languages:python/python-waitress?expand=0&rev=69
			
			
This commit is contained in:
		| @@ -1,3 +1,21 @@ | ||||
| ------------------------------------------------------------------- | ||||
| Wed Oct 30 06:49:46 UTC 2024 - Daniel Garcia <daniel.garcia@suse.com> | ||||
|  | ||||
| - Update to 3.0.1 (bsc#1232554, CVE-2024-49769): | ||||
|     * Fix a bug that would lead to Waitress busy looping on select() | ||||
|       on a half-open socket due to a race condition that existed when | ||||
|       creating a new HTTPChannel. See | ||||
|       https://github.com/Pylons/waitress/pull/435, | ||||
|       https://github.com/Pylons/waitress/issues/418 and | ||||
|       https://github.com/Pylons/waitress/security/advisories/GHSA-3f84-rpwh-47g6 | ||||
|     * No longer strip the header values before passing them to the | ||||
|       WSGI environ. See https://github.com/Pylons/waitress/pull/434 | ||||
|       and https://github.com/Pylons/waitress/issues/432 | ||||
|     * Fix a race condition in Waitress when | ||||
|       `channel_request_lookahead` is enabled that could lead to HTTP | ||||
|       request smuggling. | ||||
|     * See https://github.com/Pylons/waitress/security/advisories/GHSA-9298-4cf8-g4wj | ||||
|  | ||||
| ------------------------------------------------------------------- | ||||
| Sun Jun 30 07:59:06 UTC 2024 - Dirk Müller <dmueller@suse.com> | ||||
|  | ||||
|   | ||||
| @@ -31,7 +31,7 @@ | ||||
| %endif | ||||
| %{?sle15_python_module_pythons} | ||||
| Name:           python-waitress%{psuffix} | ||||
| Version:        3.0.0 | ||||
| Version:        3.0.1 | ||||
| Release:        0 | ||||
| Summary:        Waitress WSGI server | ||||
| License:        ZPL-2.1 | ||||
|   | ||||
| @@ -1,3 +0,0 @@ | ||||
| version https://git-lfs.github.com/spec/v1 | ||||
| oid sha256:005da479b04134cdd9dd602d1ee7c49d79de0537610d653674cc6cbde222b8a1 | ||||
| size 179393 | ||||
							
								
								
									
										
											BIN
										
									
								
								waitress-3.0.1.tar.gz
									 (Stored with Git LFS)
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										
											BIN
										
									
								
								waitress-3.0.1.tar.gz
									 (Stored with Git LFS)
									
									
									
									
										Normal file
									
								
							
										
											Binary file not shown.
										
									
								
							
		Reference in New Issue
	
	Block a user