changeset: 69055:c8701b9256cf parent: 69050:adbcba130143 parent: 69054:968bca2cab60 user: Guido van Rossum date: Tue Mar 29 13:00:28 2011 -0700 files: Misc/NEWS Objects/typeslots.inc description: Merge issue 11662. diff -r adbcba130143 -r c8701b9256cf Misc/NEWS --- a/Misc/NEWS Tue Mar 29 12:09:45 2011 -0700 +++ b/Misc/NEWS Tue Mar 29 13:00:28 2011 -0700 @@ -139,6 +139,9 @@ - Issue #11666: let help() display named tuple attributes and methods that start with a leading underscore. +- Issue #11662: Make urllib and urllib2 ignore redirections if the + scheme is not HTTP, HTTPS or FTP (CVE-2011-1521). + - Issue #5537: Fix time2isoz() and time2netscape() functions of httplib.cookiejar for expiration year greater than 2038 on 32-bit systems.