From owner-freebsd-python@freebsd.org  Fri Jun 17 17:09:17 2016
Return-Path: <owner-freebsd-python@freebsd.org>
Delivered-To: freebsd-python@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
 [IPv6:2001:1900:2254:206a::19:1])
 by mailman.ysv.freebsd.org (Postfix) with ESMTP id C9E0EA786CA
 for <freebsd-python@mailman.ysv.freebsd.org>;
 Fri, 17 Jun 2016 17:09:17 +0000 (UTC)
 (envelope-from bugzilla-noreply@freebsd.org)
Received: from mailman.ysv.freebsd.org (unknown [127.0.1.3])
 by mx1.freebsd.org (Postfix) with ESMTP id B35FB29B5
 for <freebsd-python@freebsd.org>; Fri, 17 Jun 2016 17:09:17 +0000 (UTC)
 (envelope-from bugzilla-noreply@freebsd.org)
Received: by mailman.ysv.freebsd.org (Postfix)
 id AF34BA786C9; Fri, 17 Jun 2016 17:09:17 +0000 (UTC)
Delivered-To: python@mailman.ysv.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org
 [IPv6:2001:1900:2254:206a::19:1])
 by mailman.ysv.freebsd.org (Postfix) with ESMTP id AEE08A786C8
 for <python@mailman.ysv.freebsd.org>; Fri, 17 Jun 2016 17:09:17 +0000 (UTC)
 (envelope-from bugzilla-noreply@freebsd.org)
Received: from kenobi.freebsd.org (kenobi.freebsd.org
 [IPv6:2001:1900:2254:206a::16:76])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (Client did not present a certificate)
 by mx1.freebsd.org (Postfix) with ESMTPS id 9E17C29B3
 for <python@FreeBSD.org>; Fri, 17 Jun 2016 17:09:17 +0000 (UTC)
 (envelope-from bugzilla-noreply@freebsd.org)
Received: from bugs.freebsd.org ([127.0.1.118])
 by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u5HH9H15048732
 for <python@FreeBSD.org>; Fri, 17 Jun 2016 17:09:17 GMT
 (envelope-from bugzilla-noreply@freebsd.org)
From: bugzilla-noreply@freebsd.org
To: python@FreeBSD.org
Subject: [Bug 210325] lang/python35, lang/python34, lang/python33,
 lang/python27: Backport patches for CVE-2016-5636
Date: Fri, 17 Jun 2016 17:09:17 +0000
X-Bugzilla-Reason: CC
X-Bugzilla-Type: changed
X-Bugzilla-Watch-Reason: None
X-Bugzilla-Product: Ports & Packages
X-Bugzilla-Component: Individual Port(s)
X-Bugzilla-Version: Latest
X-Bugzilla-Keywords: easy, patch, patch-ready, security
X-Bugzilla-Severity: Affects Only Me
X-Bugzilla-Who: commit-hook@freebsd.org
X-Bugzilla-Status: In Progress
X-Bugzilla-Resolution: 
X-Bugzilla-Priority: ---
X-Bugzilla-Assigned-To: rm@FreeBSD.org
X-Bugzilla-Flags: maintainer-feedback+
X-Bugzilla-Changed-Fields: 
Message-ID: <bug-210325-21822-aRklE53JlR@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-210325-21822@https.bugs.freebsd.org/bugzilla/>
References: <bug-210325-21822@https.bugs.freebsd.org/bugzilla/>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/
Auto-Submitted: auto-generated
MIME-Version: 1.0
X-BeenThere: freebsd-python@freebsd.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: FreeBSD-specific Python issues <freebsd-python.freebsd.org>
List-Unsubscribe: <https://lists.freebsd.org/mailman/options/freebsd-python>, 
 <mailto:freebsd-python-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/freebsd-python/>
List-Post: <mailto:freebsd-python@freebsd.org>
List-Help: <mailto:freebsd-python-request@freebsd.org?subject=help>
List-Subscribe: <https://lists.freebsd.org/mailman/listinfo/freebsd-python>,
 <mailto:freebsd-python-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Jun 2016 17:09:17 -0000

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D210325

--- Comment #4 from commit-hook@freebsd.org ---
A commit references this bug:

Author: rm
Date: Fri Jun 17 17:09:06 UTC 2016
New revision: 417019
URL: https://svnweb.freebsd.org/changeset/ports/417019

Log:
  lang/python[xx]: backport upstream fix for CVE-2016-5636

  Add patch for integer overflow in zipimport module to all our python port=
s.

  While I'm here, get rid of -f flag in ${RM} invocation, because ${RM} alr=
eady
  expands to rm -f, so in result we are getting something like:

  /bin/rm -f -f
/wrkdirs/usr/ports/lang/python35/work/stage/usr/local/lib/libpython3.so

  PR:           210325
  Submitted by:  Vladimir Krstulja <vlad-fbsd@acheronmedia.com>
  Security:     1d0f6852-33d8-11e6-a671-60a44ce6887b
  With hat:     python

Changes:
  head/lang/python27/Makefile
  head/lang/python27/files/patch-Modules_zipimport.c
  head/lang/python33/Makefile
  head/lang/python33/files/patch-Modules_zipimport.c
  head/lang/python34/Makefile
  head/lang/python34/files/patch-Modules_zipimport.c
  head/lang/python35/Makefile
  head/lang/python35/files/patch-Modules_zipimport.c

--=20
You are receiving this mail because:
You are on the CC list for the bug.=