All of lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Korsgaard <peter@korsgaard.com>
To: Bernd Kuhls <bernd@kuhls.net>
Cc: buildroot@uclibc.org
Subject: Re: [Buildroot] [PATCH] package/python3: security bump to version 3.11.4
Date: Sun, 18 Jun 2023 13:43:23 +0200	[thread overview]
Message-ID: <87mt0xf12c.fsf@48ers.dk> (raw)
In-Reply-To: <pan$26898$f18ae6ad$e34a44a2$ebb4cb5a@ID-313208.user.individual.net> (Bernd Kuhls's message of "Sun, 18 Jun 2023 09:08:30 +0200")

>>>>> "Bernd" == Bernd Kuhls <bernd@kuhls.net> writes:

 > Am Sat, 17 Jun 2023 23:30:56 +0200 schrieb Peter Korsgaard:
 >> Fixes the following security issues:
 >> 
 >> - gh-99889: Fixed a security in flaw in uu.decode() that could allow for
 >> directory traversal based on the input if no out_file was specified.
 >> 
 >> - gh-104049: Do not expose the local on-disk location in directory
 >> indexes
 >> produced by http.client.SimpleHTTPRequestHandler.
 >> 
 >> - gh-102153: urllib.parse.urlsplit() now strips leading C0 control and
 >> space
 >> characters following the specification for URLs defined by WHATWG in
 >> response to CVE-2023-24329.  Patch by Illia Volochii.
 >> 
 >> Refreshed patches to apply without fuzz after upstream reordered lines
 >> in Makefile.pre.in:

 > Hi Peter,

 > duplicate of https://patchwork.ozlabs.org/project/buildroot/patch/
 > 20230608165305.451682-1-bernd.kuhls@t-online.de/

Ups indeed, odd that I missed it. Committed your version, thanks.

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  reply	other threads:[~2023-06-18 11:43 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20230617213057.140556-1-peter__22050.7639039837$1687037511$gmane$org@korsgaard.com>
2023-06-18  7:08 ` [Buildroot] [PATCH] package/python3: security bump to version 3.11.4 Bernd Kuhls
2023-06-18 11:43   ` Peter Korsgaard [this message]
2023-06-17 21:30 Peter Korsgaard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87mt0xf12c.fsf@48ers.dk \
    --to=peter@korsgaard.com \
    --cc=bernd@kuhls.net \
    --cc=buildroot@uclibc.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.