Skip to content

Commit 9647966

Browse files
authored
Merge pull request #45 from ActiveState/BE-3614-python-2-7-18-9
BE-3614 Python 2.7.18.9 Release
2 parents 30222de + fb31fe2 commit 9647966

File tree

1 file changed

+50
-0
lines changed

1 file changed

+50
-0
lines changed

Misc/NEWS.d/2.7.18.9.rst

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
.. bpo: 32056
2+
.. date: 2018-03-18
3+
.. nonce:
4+
.. release date: 2024-05-15
5+
.. section: Core and Builtins
6+
7+
CVE-2017-18207
8+
9+
The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a
10+
nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and
11+
exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because
12+
Python applications "need to be prepared to handle a wide variety of exceptions.
13+
14+
.. bpo: none
15+
.. date: 2022-10-07
16+
.. nonce:
17+
.. release date: 2024-05-15
18+
.. section: Core and Builtins
19+
20+
CVE-2022-45061
21+
22+
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one
23+
path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably
24+
long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often
25+
supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they
26+
could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied
27+
supposed hostname. For example, the attack payload could be placed in the Location header of an
28+
HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.
29+
30+
.. bpo: 39421
31+
.. date: 2020-01-23
32+
.. nonce:
33+
.. release date: 2024-05-15
34+
.. section: Core and Builtins
35+
36+
CVE-2022-48560
37+
38+
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
39+
40+
.. bpo: 40791
41+
.. date: 2020-12-14
42+
.. nonce:
43+
.. release date: 2024-05-15
44+
.. section: Core and Builtins
45+
46+
CVE-2022-48566
47+
48+
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1.
49+
Constant-time-defeating optimisations were possible in the accumulator variable in
50+
hmac.compare_digest.

0 commit comments

Comments
 (0)