-
-
Notifications
You must be signed in to change notification settings - Fork 30.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update expat to 2.1.1 #70743
Comments
A new version of expat has been released. 2.2.1 addressed CVE-2015-1283. |
Christian: Is that CVE the same crash as reported by mail by Gustavo Grieco? |
No, the other problem is CVE-2016-0718. We are still looking into the matter. |
Any progress on this? It is still flagged as a Release Blocker and releases are approaching. |
Another critical bug fix will be released next Tuesday. |
Was this critical bug fix released on May 17th as promised? I will not hold up 3.5.2 for this. 3.5.2 has waited long enough. |
There is another security release for expat planned, but we can skip it for now. I'll provide a patch for Python 2 and 3 with 2.1.1 by tomorrow. |
Per http://expat.sourceforge.net/, version 2.1.1 fixes CVE-2015-1283, not 2.2.1 as mentioned in a comment. |
Christian: I don't see any checkins on this issue, and I tag 3.4.4 rc1 and 3.5.2 rc1 in about twelve hours. As I mentioned to you in person at the PyCon 2016 sprints, I'm not holding up either of these releases for the expat update. If this is still open when it's time for me to tag those releases, I'll flip this to "deferred blocker". |
New changeset d8a0a016d8d4 by Benjamin Peterson in branch '2.7': New changeset bb3ce78572f5 by Benjamin Peterson in branch '3.4': New changeset f3c36afdedae by Benjamin Peterson in branch '3.5': New changeset 77353f0106cc by Benjamin Peterson in branch 'default': |
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
The text was updated successfully, but these errors were encountered: