From nobody Wed Dec 7 14:26:38 2022 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4NS03246nmz4jyQl; Wed, 7 Dec 2022 14:26:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4NS0323SlLz3q2C; Wed, 7 Dec 2022 14:26:38 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1670423198; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=aH/lVfCaENJ2b0t51U72F8WAIa7L4EAeCiCiIiMpsFc=; b=ip1tGqYIcEo2zztOp9rm9pE4gcy5T7GrLDUAbd+nQLoYhrH+eDsp2YnbqReUe3YiGb0er1 k6KPLHGC0jW9WVk4tH4y2P2OvWTUkCp9RYV+NFI2YMPSp2n7l65Zek4IxTYLlNh4hAq2Yt 96q5aUPholh+9idFt78FqBvkYILsxyO1ekfi8OLTn6jlqzizqI+YqNQgvFdzsH7GPMB4Ak 4gA/8nPrmm/jI6NWr4Ww/GHy2HaEDP3Zeb29OLHF8uPu4XJmxtkUwaZvjCjXCGbfF6ETMZ 4CIIGEb1la94/Jv6udspOMfwBwGJSgODa4QhtILJsmv0t91kLvM9Y8BgZvC1ww== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1670423198; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=aH/lVfCaENJ2b0t51U72F8WAIa7L4EAeCiCiIiMpsFc=; b=OEZHyXt39RFQdqI0/utWInP3uf3t1qSpFtDAr6rvSijtLcSNk6cixeXFytL/j7lFIhvB/W 6AyblYZdaI5YMcHsLnRFpwK5ZS8h5QVPJS8DERSxv/uwew4FGntc4IulKTVLXHTSMoY914 FkvSxl+xfrP7YkfvfYu6mCUWZ5Ej7G9fRoIp8fOznHXyk6HwsN36P80UWiy1x/mo25icAX F2yN6v41914NgjdlVSj19xbCBsD1VulbiPKEtntVFA0KjlMu9lH3zeTnVYxlISIiv2T2Ou mfkFkLNmuyTwOz8RnCaE4zCDQw6TVfATizNZY2XMHDXxZepjFmjxz2raIp5evw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1670423198; a=rsa-sha256; cv=none; b=osyPnj24mskvNPh6gnsPsOdKxHCGr9SEcL2ou+boVz9ckBGaW2RIyxJLJ45Fb/lef/KD+1 sEWz1vGzVv2ssyHA6hBenv10TV/2fY1/oBAJJNBQVJr6ZkcO9V98u+ACOkCBZtPKLk0Lez Flxzr/y0aFI9jl3LIiWxK28HJHSOhMUnbIT0z7PnRGpwoKHpt0wgk8bCxR60hqYWsMQbjC Hdf+ByYaffjPr7ahScuqBOslCkV2EXNysz0j30p1gRR6RwRomI/3glDzYOkoDmD+Hvn/e5 EZTn1eh4hmjGWCXGrIOeHBaCFUa9k5YIjkz7hniq1pvX6DLD2AMwmrtdA/WajQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4NS03226QszKZm; Wed, 7 Dec 2022 14:26:38 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 2B7EQc0A056699; Wed, 7 Dec 2022 14:26:38 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 2B7EQcMO056698; Wed, 7 Dec 2022 14:26:38 GMT (envelope-from git) Date: Wed, 7 Dec 2022 14:26:38 GMT Message-Id: <202212071426.2B7EQcMO056698@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Wen Heping Subject: git: 8626b3d3114f - main - security/vuxml: Document python-3.11 vulnerabilities List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: wen X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 8626b3d3114fd21d4c1153ec9cb161dfd2d5fee4 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by wen: URL: https://cgit.FreeBSD.org/ports/commit/?id=8626b3d3114fd21d4c1153ec9cb161dfd2d5fee4 commit 8626b3d3114fd21d4c1153ec9cb161dfd2d5fee4 Author: Wen Heping AuthorDate: 2022-12-07 14:25:15 +0000 Commit: Wen Heping CommitDate: 2022-12-07 14:25:15 +0000 security/vuxml: Document python-3.11 vulnerabilities --- security/vuxml/vuln/2022.xml | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/security/vuxml/vuln/2022.xml b/security/vuxml/vuln/2022.xml index 8a25f8c107f1..24f753c04b47 100644 --- a/security/vuxml/vuln/2022.xml +++ b/security/vuxml/vuln/2022.xml @@ -1,3 +1,41 @@ + + Python -- multiple vulnerabilities + + + python311 + 3.11.1 + + + + +

Python reports:

+
+

gh-100001: python -m http.server no longer allows terminal control characters sent + within a garbage request to be printed to the stderr server log. + This is done by changing the http.server BaseHTTPRequestHandler .log_message method + to replace control characters with a \xHH hex escape before printing.

+

gh-87604: Avoid publishing list of active per-interpreter audit hooks via the gc module.

+

gh-98433: The IDNA codec decoder used on DNS hostnames by socket or asyncio related + name resolution functions no longer involves a quadratic algorithm. This prevents a + potential CPU denial of service if an out-of-spec excessive length hostname involving + bidirectional characters were decoded. Some protocols such as urllib http 3xx redirects + potentially allow for an attacker to supply such a name.

+

gh-98739: Update bundled libexpat to 2.5.0.

+

gh-97612: Fix a shell code injection vulnerability in the get-remote-certificate.py example + script. The script no longer uses a shell to run openssl commands. Issue reported and + initial fix by Caleb Shortt. Patch by Victor Stinner.

+
+ +
+ + https://docs.python.org/3/whatsnew/changelog.html#changelog + + + 2022-09-28 + 2022-12-07 + +
+ go -- multiple vulnerabilities