Steve Dower <steve.do...@python.org> added the comment:

> I added 
> https://python-security.readthedocs.io/vuln/unsafe-dll-load-windows-7.html to 
> track fixes in all branches.

Thanks, Victor!

Python 2.7 and 3.5 are not vulnerable. The issue was added in 3.6 when I added 
support for installing Python into a long path name on up-to-date OS, which 
required dynamically loading an OS function. That dynamic load was the problem.

----------

_______________________________________
Python tracker <rep...@bugs.python.org>
<https://bugs.python.org/issue39401>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to