lp:ubuntu/natty-security/python2.6
- Get this branch:
- bzr branch lp:ubuntu/natty-security/python2.6
Branch merges
Branch information
Recent revisions
- 68. By Jamie Strandboge
-
* SECURITY UPDATE: fix hash randomization DoS
- debian/patches/ CVE-2012- 1150.diff: add -R command-line option and
PYTHONHASHSEED environment variable, to provide an opt-in way to protect
against denial of service attacks due to hash collisions within the dict
and set types.
- CVE-2012-1150
* SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon
malformed POST request
- debian/patches/ CVE-2012- 0845.diff: break if don't receive EOF in
Lib/SimpleXMLRPCSer ver.py
- CVE-2012-0845
* SECURE UPDATE: http://bugs.python. org/issue13512
- debian/patches/ CVE-2011- 4944.diff: create ~/.pypirc securely
- CVE-2011-4944
* SECURITY UPDATE: Fix CGIHTTPServer information disclosure.
- debian/patches/ CVE-2011- 1015.diff: Relative paths are now collapsed
within the url properly before looking in cgi_directories.
- CVE-2011-1015
* SECURITY UPDATE: fix XSS in SimpleHTTPServer
- debian/patches/ CVE-2011- 4940.diff: add a charset parameter to the
Content-type
- CVE-2011-4940
* SECURITY UPDATE: update urllib and urllib2 for invalid redirections
- debian/patches/ CVE-2011- 1521.diff: only process Location headers for
http, https, and ftp
- http://bugs.python. org/issue11662
- CVE-2011-1521 - 65. By Matthias Klose
-
Revert the libpython2.6 and python2.6 dependencies on python2.6-dev.
Most packages are rebuilt. Remaining issues have to be fixed in
the packages. - 62. By Matthias Klose
-
libpython2.6: Depend on python2.6-dev for a limited time to
get packages rebuilt, which depend on python just python-dev,
but pull in python2.6 by other build-dependencies and fail
to build by missing header files found in python2.6-dev.
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp:ubuntu/quantal/python2.6