[issue26556] Update expat to 2.2.1

2016-06-11 Thread Roundup Robot
Roundup Robot added the comment: New changeset d8a0a016d8d4 by Benjamin Peterson in branch '2.7': upgrade expt to 2.1.1 (closes #26556) https://hg.python.org/cpython/rev/d8a0a016d8d4 New changeset bb3ce78572f5 by Benjamin Peterson in branch '3.4': upgrade expt to 2.1.1 (closes #26556) https://hg

[issue26556] Update expat to 2.2.1

2016-06-11 Thread Larry Hastings
Larry Hastings added the comment: Christian: I don't see any checkins on this issue, and I tag 3.4.4 rc1 and 3.5.2 rc1 in about twelve hours. As I mentioned to you in person at the PyCon 2016 sprints, I'm not holding up either of these releases for the expat update. If this is still open whe

[issue26556] Update expat to 2.2.1

2016-06-09 Thread Brian Martin
Brian Martin added the comment: Per http://expat.sourceforge.net/, version 2.1.1 fixes CVE-2015-1283, not 2.2.1 as mentioned in a comment. -- nosy: +Brian Martin ___ Python tracker

[issue26556] Update expat to 2.2.1

2016-06-07 Thread Christian Heimes
Christian Heimes added the comment: There is another security release for expat planned, but we can skip it for now. I'll provide a patch for Python 2 and 3 with 2.1.1 by tomorrow. -- ___ Python tracker __

[issue26556] Update expat to 2.2.1

2016-06-07 Thread Larry Hastings
Larry Hastings added the comment: Was this critical bug fix released on May 17th as promised? I will not hold up 3.5.2 for this. 3.5.2 has waited long enough. -- ___ Python tracker ___

[issue26556] Update expat to 2.2.1

2016-05-31 Thread Mirko Dziadzka
Changes by Mirko Dziadzka : -- nosy: +mirko.dziadzka ___ Python tracker ___ ___ Python-bugs-list mailing list Unsubscribe: https://ma

[issue26556] Update expat to 2.2.1

2016-05-12 Thread Christian Heimes
Christian Heimes added the comment: Another critical bug fix will be released next Tuesday. -- ___ Python tracker ___ ___ Python-bugs-

[issue26556] Update expat to 2.2.1

2016-05-12 Thread Ned Deily
Ned Deily added the comment: Any progress on this? It is still flagged as a Release Blocker and releases are approaching. -- ___ Python tracker ___

[issue26556] Update expat to 2.2.1

2016-05-12 Thread Ned Deily
Changes by Ned Deily : -- nosy: +ned.deily ___ Python tracker ___ ___ Python-bugs-list mailing list Unsubscribe: https://mail.python.

[issue26556] Update expat to 2.2.1

2016-03-19 Thread Christian Heimes
Christian Heimes added the comment: No, the other problem is CVE-2016-0718. We are still looking into the matter. -- ___ Python tracker ___ __

[issue26556] Update expat to 2.2.1

2016-03-19 Thread Larry Hastings
Larry Hastings added the comment: Christian: Is that CVE the same crash as reported by mail by Gustavo Grieco? -- ___ Python tracker ___ _

[issue26556] Update expat to 2.2.1

2016-03-14 Thread Christian Heimes
New submission from Christian Heimes: A new version of expat has been released. 2.2.1 addressed CVE-2015-1283. -- components: Extension Modules, XML messages: 261741 nosy: benjamin.peterson, christian.heimes, georg.brandl, larry priority: release blocker severity: normal stage: needs pat