summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Matthias Klose [Thu, 14 May 2026 03:00:00 +0000 (10:00 +0700)]
deb-setup
# DP: Don't include /usr/local/include and /usr/local/lib as gcc search paths
# DP: Don't include /usr/local/include and /usr/local/lib as gcc search paths
Gbp-Pq: Name deb-setup.diff
Arnaud Rebillout [Thu, 14 May 2026 03:00:00 +0000 (10:00 +0700)]
python3.9 (3.9.2-1+deb11u7) bullseye-security; urgency=high
* Non-maintainer upload by the LTS Team.
* Apply upstream patches for the following CVEs:
- CVE-2025-13462: Incorrect parsing of TarInfo header when GNU long name
and type AREGTYPE are combined
- CVE-2026-2297: SourcelessFileLoader does not use io.open_code()
- CVE-2026-3644: Reject control characters in more places in
http.cookies.Morsel (follow-up of patch for CVE-2026-0672)
- CVE-2026-4224: pyexpat.c: Unbounded C recursion in conv_content_model
causes crash
- CVE-2026-4519: Reject leading dashes in webbrowser.open()
[dgit import unpatched python3.9 3.9.2-1+deb11u7]
Arnaud Rebillout [Thu, 14 May 2026 03:00:00 +0000 (10:00 +0700)]
Import python3.9_3.9.2-1+deb11u7.debian.tar.xz
[dgit import tarball python3.9 3.9.2-1+deb11u7 python3.9_3.9.2-1+deb11u7.debian.tar.xz]
Matthias Klose [Sun, 28 Feb 2021 17:03:44 +0000 (18:03 +0100)]
Import python3.9_3.9.2.orig.tar.xz
[dgit import orig python3.9_3.9.2.orig.tar.xz]