https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=246984

--- Comment #13 from Dani <i.d...@outlook.com> ---
(In reply to Kubilay Kocak from comment #12)

Hi koobs, thanks for your feedback.

- Patch "Fix CVE-2020-8492" can be marked obsolate due to the patch of Danilo.

- bug #246808 used the commit which has been made in the Git "master"-Branch.
The commits Danilo and i used, were the ones that have "specially" been
made/backported to the different releases (eg. 3.6, 3.7, 3.5). See section
"Timeline":
https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html

- The summary can best be done by Danilo i guess. What's basically important
is:
  - A new version of Python 3.8 has been released, which fixed all open CVE's
(v 3.8.3)
  - No new version released !yet! for: Python 3.5, 3.6, 3.7 
  - CVE-2019-18348 has a fix ready and merged for all python versions:
https://bugs.python.org/issue38576
  - CVE-2020-8492 has a fiy ready and merged for python 3.6, 3.7, 3.8, 3.9
(https://bugs.python.org/issue39503) but not for 3.5
(https://github.com/python/cpython/pull/19305)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.
_______________________________________________
freebsd-python@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-python
To unsubscribe, send any mail to "freebsd-python-unsubscr...@freebsd.org"

Reply via email to