Re: CVE-2019-16935/python*

2019-09-30 Thread Ola Lundqvist
Hi jython and pypy-lib added now. Also marked it as ignored for LTS. Best regards // Ola On Mon, 30 Sep 2019 at 12:48, Sylvain Beucler wrote: > Hi, > > On 28/09/2019 22:36, Ola Lundqvist wrote: > > I have looked a little into CVE-2019-16935. My conclusion is that the > > package is

Re: CVE-2019-16935/python*

2019-09-30 Thread Sylvain Beucler
Hi, On 28/09/2019 22:36, Ola Lundqvist wrote: > I have looked a little into CVE-2019-16935. My conclusion is that the > package is vulnerable but I could not really judge its severity. I have > a question though. If we find that we should correct it, shouldn't we > correct also jython and