Skip to content

Conversation

@ambv
Copy link
Contributor

@ambv ambv commented Aug 29, 2021

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Łukasz Langa [email protected].
(cherry picked from commit 3fc5d84)

Co-authored-by: Victor Stinner [email protected]

https://bugs.python.org/issue44394

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Łukasz Langa <[email protected]>.
(cherry picked from commit 3fc5d84)

Co-authored-by: Victor Stinner <[email protected]>
@ned-deily ned-deily merged commit 79101b8 into python:3.7 Aug 31, 2021
ned-deily pushed a commit to ned-deily/cpython that referenced this pull request Aug 31, 2021
…onGH-28042)

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Victor Stinner <[email protected]>

Co-authored-by: Łukasz Langa <[email protected]>.
(cherry picked from commit 3fc5d84)
ned-deily added a commit that referenced this pull request Aug 31, 2021
…H-28080)

Update the vendored copy of libexpat to 2.4.1 (from 2.2.8) to get the
fix for the CVE-2013-0340 "Billion Laughs" vulnerability. This copy
is most used on Windows and macOS.

Co-authored-by: Victor Stinner <[email protected]>

Co-authored-by: Łukasz Langa <[email protected]>.
(cherry picked from commit 3fc5d84)
@ambv ambv deleted the backport-3fc5d84-3.7 branch September 17, 2021 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants