Skip to content

Conversation

@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Aug 29, 2021

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Łukasz Langa [email protected]
(cherry picked from commit 3fc5d84)

Co-authored-by: Victor Stinner [email protected]

https://bugs.python.org/issue44394

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Łukasz Langa <[email protected]>
(cherry picked from commit 3fc5d84)

Co-authored-by: Victor Stinner <[email protected]>
@miss-islington
Copy link
Contributor Author

@vstinner and @ambv: Status check is done, and it's a success ✅ .

@miss-islington
Copy link
Contributor Author

@vstinner and @ambv: Status check is done, and it's a success ✅ .

@miss-islington
Copy link
Contributor Author

@vstinner and @ambv: Status check is done, and it's a success ✅ .

@ambv ambv merged commit c9c2a0b into python:3.8 Aug 29, 2021
@miss-islington miss-islington deleted the backport-3fc5d84-3.8 branch August 29, 2021 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants