mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-03 21:21:08 -09:00
Fixes the following security issues: - bpo-42988: CVE-2021-3426: Remove the getfile feature of the pydoc module which could be abused to read arbitrary files on the disk (directory traversal vulnerability). Moreover, even source code of Python modules can contain sensitive data like passwords. Vulnerability reported by David Schwörer. - bpo-43285: ftplib no longer trusts the IP address value returned from the server in response to the PASV command by default. This prevents a malicious FTP server from using the response to probe IPv4 address and port combinations on the client network. Code that requires the former vulnerable behavior may set a trust_server_pasv_ipv4_address attribute on their ftplib.FTP instances to True to re-enable it. - bpo-43439: Add audit hooks for gc.get_objects(), gc.get_referrers() and gc.get_referents(). Patch by Pablo Galindo. Note: 3.9.3 was recalled due to introducing unintentional ABI incompatibility, and fixes re-released as 3.9.4: https://www.python.org/downloads/release/python-394/ Add host-autoreconf-archive, as it is needed for autoreconf since:064bc07f24Signed-off-by: Peter Korsgaard <peter@korsgaard.com> (cherry picked from commita14ce17ca6) Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
314 B
314 B