Re: [LFS Trac] #5859: python3-3.14.3

"LFS Trac" ([email protected] via lfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.book
Message-ID <[email protected]>
#5859: python3-3.14.3
-------------------------+-----------------------
 Reporter:  Bruce Dubbs  |       Owner:  lfs-book
     Type:  enhancement  |      Status:  closed
 Priority:  high         |   Milestone:  13.0
Component:  Book         |     Version:  git
 Severity:  normal       |  Resolution:  fixed
 Keywords:               |
-------------------------+-----------------------
Changes (by Douglas R. Reno):

 * priority:  normal => high

Comment:

 Security changes for Python-3.14.3:

 {{{
 Security

     gh-144125: BytesGenerator will now refuse to serialize (write) headers
 that are
 unsafely folded or delimited; see verify_generated_headers. (Contributed
 by Bas
 Bloemsaat and Petr Viktorin in gh-121650).

     gh-143935: Fixed a bug in the folding of comments when flattening an
 email message
 using a modern email policy. Comments consisting of a very long sequence
 of non-foldable
 characters could trigger a forced line wrap that omitted the required
 leading space on
 the continuation line, causing the remainder of the comment to be
 interpreted as a new
 header field. This enabled header injection with carefully crafted inputs.

     gh-143925: Reject control characters in data: URL media types.

     gh-143919: Reject control characters in http.cookies.Morsel fields and
 values.

     gh-143916: Reject C0 control characters within wsgiref.headers.Headers
 fields,
 values, and parameters.
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/lfs/ticket/5859#comment:4>
LFS Trac <https://wiki.linuxfromscratch.org/lfs/>
Linux From Scratch: Your Distro, Your Rules.

-- 
http://lists.linuxfromscratch.org/sympa/info/lfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.