Format: 1.8 Date: Tue, 20 Aug 2019 13:12:48 -0400 Source: python3.6 Binary: python3.6 python3.6-venv libpython3.6-stdlib python3.6-minimal libpython3.6-minimal libpython3.6 python3.6-examples python3.6-dev libpython3.6-dev libpython3.6-testsuite idle-python3.6 python3.6-doc python3.6-dbg libpython3.6-dbg Architecture: s390x Version: 3.6.8-1~18.04.2 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: idle-python3.6 - IDE for Python (v3.6) using Tkinter libpython3.6 - Shared Python runtime library (version 3.6) libpython3.6-dbg - Debug Build of the Python Interpreter (version 3.6) libpython3.6-dev - Header files and a static library for Python (v3.6) libpython3.6-minimal - Minimal subset of the Python language (version 3.6) libpython3.6-stdlib - Interactive high-level object-oriented language (standard library libpython3.6-testsuite - Testsuite for the Python standard library (v3.6) python3.6 - Interactive high-level object-oriented language (version 3.6) python3.6-dbg - Debug Build of the Python Interpreter (version 3.6) python3.6-dev - Header files and a static library for Python (v3.6) python3.6-doc - Documentation for the high-level object-oriented language Python python3.6-examples - Examples for the Python language (v3.6) python3.6-minimal - Minimal subset of the Python language (version 3.6) python3.6-venv - Interactive high-level object-oriented language (pyvenv binary, v Changes: python3.6 (3.6.8-1~18.04.2) bionic-security; urgency=medium . * SECURITY UPDATE: incorrect cookie domain check - debian/patches/CVE-2018-20852.patch: prefix dot in domain for proper subdomain validation in Lib/http/cookiejar.py, Lib/test/test_http_cookiejar.py. - CVE-2018-20852 * SECURITY UPDATE: NULL pointer dereference via X509 certificate - debian/patches/CVE-2019-5010.patch: fix segfault in ssl cert parser in Lib/test/talos-2019-0758.pem, Lib/test/test_ssl.py, Modules/_ssl.c. - CVE-2019-5010 * SECURITY UPDATE: improper handling of unicode encoding - debian/patches/CVE-2019-9636.patch: add check for characters in netloc that normalize to separators in Doc/library/urllib.parse.rst, Lib/test/test_urlparse.py, Lib/urllib/parse.py. - CVE-2019-9636 * SECURITY UPDATE: HTTP header injection - debian/patches/CVE-2019-9740.patch: disallow control chars in http URLs in Lib/http/client.py, Lib/test/test_urllib.py, Lib/test/test_xmlrpc.py. - CVE-2019-9740 - CVE-2019-9947 * SECURITY UPDATE: urllib support the local_file: scheme - debian/patches/CVE-2019-9948.patch: disallow file reading in Lib/urllib/request.py, Lib/test/test_urllib.py. - CVE-2019-9948 * SECURITY UPDATE: incomplete fix for CVE-2019-9636 - debian/patches/CVE-2019-10160-1.patch: fix handling of pre-normalization characters in urlsplit() in Lib/test/test_urlparse.py, Lib/urllib/parse.py. - debian/patches/CVE-2019-10160-2.patch: correct fix to handle decomposition in usernames in Lib/test/test_urlparse.py, Lib/urllib/parse.py. - CVE-2019-10160 Checksums-Sha1: ca2bd60c71e52beef80101c80501042cc29f3dea 10177692 libpython3.6-dbg_3.6.8-1~18.04.2_s390x.deb 80554385df421fd12d16744a5791cfa85b6139c8 2814740 libpython3.6-dev_3.6.8-1~18.04.2_s390x.deb d4023a8698b9a5b46ad29b7fd6b10ab4b92de2c0 529560 libpython3.6-minimal_3.6.8-1~18.04.2_s390x.deb 257e773eadfc5a44acc2442ff242824fd8f3e169 1666504 libpython3.6-stdlib_3.6.8-1~18.04.2_s390x.deb 30a8d2c9ba93e575e84e17d8bc8fa7bc31cc0e4a 1284508 libpython3.6_3.6.8-1~18.04.2_s390x.deb c12fd20e3d5df458433aa2e8ae4326e6a0d935c1 14785864 python3.6-dbg_3.6.8-1~18.04.2_s390x.deb 42efafe97f85ff588a3f195d7d2216f1b328e98b 508032 python3.6-dev_3.6.8-1~18.04.2_s390x.deb 0917362086a911f6f868905ad0a56bcfbec11d2d 1487396 python3.6-minimal_3.6.8-1~18.04.2_s390x.deb 3622c9edc9dde0ffd10f13f31bdf8b0e379470b5 6184 python3.6-venv_3.6.8-1~18.04.2_s390x.deb c1b6ae6d0d299537aa4d089cc17a9cda69f7d56b 11956 python3.6_3.6.8-1~18.04.2_s390x.buildinfo d9b73789a11920de3103e7eb76b2bd2486e283b6 201544 python3.6_3.6.8-1~18.04.2_s390x.deb Checksums-Sha256: 9fa77c8a84a96297a3d222f3ee1a89517f635a0d6093d3cb513e782d22335a11 10177692 libpython3.6-dbg_3.6.8-1~18.04.2_s390x.deb 6a050f8499eb624b41f8f6fd1fb079031a43a0f00f0cca3e98136659a005bc58 2814740 libpython3.6-dev_3.6.8-1~18.04.2_s390x.deb 5616fe65fe5b904962949522bc1a2422447ef00e37258147f4a91af5c7a233c1 529560 libpython3.6-minimal_3.6.8-1~18.04.2_s390x.deb ce118ca0a5c2cb1ea3951abed59f9ffcf4256693faad73c9343aabd5358b96c7 1666504 libpython3.6-stdlib_3.6.8-1~18.04.2_s390x.deb b0e525ec85303179d963fbe44ef4d43928badc57f535c3c4d584c61865746fed 1284508 libpython3.6_3.6.8-1~18.04.2_s390x.deb 116becdf795e32ff989cbb4e16803556769a5569b8978a23a30a819f0b0b8739 14785864 python3.6-dbg_3.6.8-1~18.04.2_s390x.deb 6dd8220083560399ab3bb25b9ba463ae23fc35e611f36f82252f553c7528e572 508032 python3.6-dev_3.6.8-1~18.04.2_s390x.deb 6584290fe48e992cca12bf5708d2a9b8cca413924dfadb58d949089fc69f7692 1487396 python3.6-minimal_3.6.8-1~18.04.2_s390x.deb cab18d28ef052280d7b443ea06acc4df345c0ca74e81cb859146f358fc013bac 6184 python3.6-venv_3.6.8-1~18.04.2_s390x.deb 43029e543a57994d79ceaa93238ffc19d9e40af59b18a8b4f0e8b89a9c581635 11956 python3.6_3.6.8-1~18.04.2_s390x.buildinfo 33b79458a7c81d4792d6bfb0881abcde992ec4168dd531936afa5b1d59349899 201544 python3.6_3.6.8-1~18.04.2_s390x.deb Files: 4146acb51104fb698daa778ef4cccba5 10177692 debug optional libpython3.6-dbg_3.6.8-1~18.04.2_s390x.deb ab66b0042d5750b0ffd58ba631410a48 2814740 libdevel optional libpython3.6-dev_3.6.8-1~18.04.2_s390x.deb c0c2bcb17ed1427c0386559fb0fe9908 529560 python optional libpython3.6-minimal_3.6.8-1~18.04.2_s390x.deb 06e7a2201ed7ac543f587950637b1eef 1666504 python optional libpython3.6-stdlib_3.6.8-1~18.04.2_s390x.deb 23dd1b110f549b02befbaf191682d57c 1284508 libs optional libpython3.6_3.6.8-1~18.04.2_s390x.deb fb091e4f189ca7a5bb82daeb27737e49 14785864 debug optional python3.6-dbg_3.6.8-1~18.04.2_s390x.deb 829ba373ee5056165b564fc2b9e615e7 508032 python optional python3.6-dev_3.6.8-1~18.04.2_s390x.deb 1dfac689634d34b9cd5071ee1a3241dd 1487396 python optional python3.6-minimal_3.6.8-1~18.04.2_s390x.deb 5d8545108be23adfc0daa291748b4d94 6184 python optional python3.6-venv_3.6.8-1~18.04.2_s390x.deb b5d1bbff4881a2a4c6043d7f22a74fd5 11956 python optional python3.6_3.6.8-1~18.04.2_s390x.buildinfo 4473f42d03525ff4050b391059efc1c0 201544 python optional python3.6_3.6.8-1~18.04.2_s390x.deb