Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package python38 for openSUSE:Factory checked in at 2023-09-06 18:59:26 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/python38 (Old) and /work/SRC/openSUSE:Factory/.python38.new.1766 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python38" Wed Sep 6 18:59:26 2023 rev:40 rq:1109196 version:3.8.18 Changes: -------- --- /work/SRC/openSUSE:Factory/python38/python38.changes 2023-08-04 15:03:51.192441300 +0200 +++ /work/SRC/openSUSE:Factory/.python38.new.1766/python38.changes 2023-09-06 19:03:39.991265304 +0200 @@ -1,0 +2,17 @@ +Wed Sep 6 06:09:33 UTC 2023 - Daniel Garcia <[email protected]> + +- Update to 3.8.18 (bsc#1214692): + - gh-108310: Fixed an issue where instances of ssl.SSLSocket were + vulnerable to a bypass of the TLS handshake and included + protections (like certificate verification) and treating sent + unencrypted data as if it were post-handshake TLS encrypted data. + Security issue reported as CVE-2023-40217 by Aapo Oksman. Patch by + Gregory P. Smith. + - gh-107845: tarfile.data_filter() now takes the location of + symlinks into account when determining their target, so it will no + longer reject some valid tarballs with + LinkOutsideDestinationError. + - gh-107565: Update multissltests and GitHub CI workflows to use + OpenSSL 1.1.1v, 3.0.10, and 3.1.2. + +------------------------------------------------------------------- Old: ---- Python-3.8.17.tar.xz Python-3.8.17.tar.xz.asc New: ---- Python-3.8.18.tar.xz Python-3.8.18.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ python38.spec ++++++ --- /var/tmp/diff_new_pack.4HFlyf/_old 2023-09-06 19:03:43.783400486 +0200 +++ /var/tmp/diff_new_pack.4HFlyf/_new 2023-09-06 19:03:43.787400628 +0200 @@ -92,7 +92,7 @@ %define dynlib() %{sitedir}/lib-dynload/%{1}.cpython-%{abi_tag}-%{archname}-%{_os}%{?_gnu}%{?armsuffix}.so %bcond_without profileopt Name: %{python_pkg_name}%{psuffix} -Version: 3.8.17 +Version: 3.8.18 Release: 0 Summary: Python 3 Interpreter License: Python-2.0 ++++++ Python-3.8.17.tar.xz -> Python-3.8.18.tar.xz ++++++ /work/SRC/openSUSE:Factory/python38/Python-3.8.17.tar.xz /work/SRC/openSUSE:Factory/.python38.new.1766/Python-3.8.18.tar.xz differ: char 27, line 1
