SHA256
1
0
forked from pool/python310

Accepting request 1000538 from devel:languages:python:Factory

Add references to bsc#1202624, CVE-2021-28861

OBS-URL: https://build.opensuse.org/request/show/1000538
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/python310?expand=0&rev=20
This commit is contained in:
Dominique Leuenberger 2022-09-01 20:10:16 +00:00 committed by Git OBS Bridge
commit 2efb08548d

View File

@ -10,7 +10,7 @@ Tue Aug 2 17:13:37 UTC 2022 - Matej Cepl <mcepl@suse.com>
- gh-87389: http.server: Fix an open redirection vulnerability
in the HTTP server when an URI path starts with //.
Vulnerability discovered, and initial fix proposed, by Hamza
Avvan.
Avvan. (bsc#1202624, CVE-2021-28861)
- gh-92888: Fix memoryview use after free when accessing the
backing buffer in certain cases.
- gh-95355: _PyPegen_Parser_New now properly detects token