[ubuntu/xenial-security] python2.7 2.7.12-1ubuntu0~16.04.12 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Wed Jul 22 13:10:17 UTC 2020


python2.7 (2.7.12-1ubuntu0~16.04.12) xenial-security; urgency=medium

  * SECURITY UPDATE: Misleading information
    - debian/patches/CVE-2019-17514.patch: explain that the orderness of the
      of the result is system-dependant in Doc/library/glob.rst.
    - CVE-2019-17514
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2019-9674.patch: add pitfalls to
      zipfile module doc in Doc/library/zipfile.rst,
      Misc/NEWS.d/next/Documentation/2019-06-04-09-29-00.bpo-36260.WrGuc-.rst.
    - CVE-2019-9674
  * SECURITY UPDATE: Infinite loop
    - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the
      tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py.
    - CVE-2019-20907

Date: 2020-07-21 16:02:18.284288+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.12
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list