[Security-sig] CVE-2018-1000117: Buffer overflow vulnerability in os.symlink on Windows

2018-03-07 Thread Steve Dower
On February 27th, 2018, the Python Security Response team was notified of a buffer overflow issue in the os.symlink() method on Windows. The issue affects all versions of Python between 3.2 and 3.6.4, including the 3.7 beta releases. It has been patched for the next releases of 3.4, 3.5, 3.6 an

[Security-sig] Re: CVE-2018-1000117: Buffer overflow vulnerability in os.symlink on Windows

2018-03-07 Thread Steve Dower
Just FYI, I got bounced from the security-announce list, so I'll be posting this again once our beloved FLUFL gives me the right permissions. I'll include this list on the re-send as well, just in case it helps with threading. On 07Mar2018 0834, Steve Dower wrote: On February 27th, 2018, the

[Security-sig] CVE-2018-1000117: Buffer overflow vulnerability in os.symlink on Windows

2018-03-07 Thread Steve Dower
On February 27th, 2018, the Python Security Response team was notified of a buffer overflow issue in the os.symlink() method on Windows. The issue affects all versions of Python between 3.2 and 3.6.4, including the 3.7 beta releases. It has been patched for the next releases of 3.4, 3.5, 3.6 and 3.