|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2012-9135 (python3)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 16 Update: python3-3.2.3-2.fc16
Date:  Tue, 19 Jun 2012 14:53:34 +0000
Message-ID:  <20120619145336.4FECC20A10@bastion01.phx2.fedoraproject.org>
Archive‑link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-9135 2012-06-08 23:26:55 -------------------------------------------------------------------------------- Name : python3 Product : Fedora 16 Version : 3.2.3 Release : 2.fc16 URL : http://www.python.org/ Summary : Version 3 of the Python programming language aka Python 3000 Description : Python 3 is a new version of the language that is incompatible with the 2.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed. -------------------------------------------------------------------------------- Update Information: Fixes debug build systemtap support. Rebase of python3 from 3.2.1 to 3.2.3 bringing in security fixes, along with many other bug fixes. The compiled *.pyc and *.pyo files are now properly compiled so python3 doesn't try to recompile them over and over on runtime anymore. -------------------------------------------------------------------------------- ChangeLog: * Wed May 30 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 3.2.3-2 - fix tapset for debug build * Thu Apr 12 2012 David Malcolm <dmalcolm@redhat.com> - 3.2.3-1 - 3.2.3; refresh patch 102 (lib64); fix test_gdb (patches 152 and 153) * Thu Feb 9 2012 Thomas Spura <tomspur@fedoraproject.org> - 3.2.1-4 - use newly installed python for byte compiling (now for real) * Sun Feb 5 2012 Thomas Spura <tomspur@fedoraproject.org> - 3.2.1-3 - use newly installed python for byte compiling (#787498) * Thu Sep 1 2011 David Malcolm <dmalcolm@redhat.com> - 3.2.1-2.2 - disable parts of test_io on ppc (rhbz#732998) - use "--findleaks --verbose" when running test suite - re-enable and fix the --with-tsc option on ppc64, and rework it on 32-bit ppc to avoid aliasing violations (patch 130; rhbz#698726) - add %python3_version to the rpm macros (rhbz#719082) * Tue Aug 23 2011 David Malcolm <dmalcolm@redhat.com> - 3.2.1-2.1 - don't use --with-tsc on ppc64 debug builds (rhbz#698726) -------------------------------------------------------------------------------- References: [ 1 ] Bug #750555 - CVE-2012-1150 python: hash table collisions CPU usage DoS (oCERT-2011-003) https://bugzilla.redhat.com/show_bug.cgi?id=750555 [ 2 ] Bug #789790 - CVE-2012-0845 python: SimpleXMLRPCServer CPU usage DoS via malformed XML-RPC request https://bugzilla.redhat.com/show_bug.cgi?id=789790 [ 3 ] Bug #812068 - python: SSL CBC IV vulnerability (CVE-2011-3389, BEAST) https://bugzilla.redhat.com/show_bug.cgi?id=812068 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python3' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds