-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 22 Aug 2020 12:03:02 +0200 Source: python2.7 Binary: python2.7 libpython2.7-stdlib python2.7-minimal libpython2.7-minimal libpython2.7 python2.7-examples python2.7-dev libpython2.7-dev libpython2.7-testsuite idle-python2.7 python2.7-doc python2.7-dbg libpython2.7-dbg Architecture: source all amd64 Version: 2.7.13-2+deb9u4 Distribution: stretch-security Urgency: medium Maintainer: Matthias Klose <doko@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: idle-python2.7 - IDE for Python (v2.7) using Tkinter libpython2.7 - Shared Python runtime library (version 2.7) libpython2.7-dbg - Debug Build of the Python Interpreter (version 2.7) libpython2.7-dev - Header files and a static library for Python (v2.7) libpython2.7-minimal - Minimal subset of the Python language (version 2.7) libpython2.7-stdlib - Interactive high-level object-oriented language (standard library libpython2.7-testsuite - Testsuite for the Python standard library (v2.7) python2.7 - Interactive high-level object-oriented language (version 2.7) python2.7-dbg - Debug Build of the Python Interpreter (version 2.7) python2.7-dev - Header files and a static library for Python (v2.7) python2.7-doc - Documentation for the high-level object-oriented language Python python2.7-examples - Examples for the Python language (v2.7) python2.7-minimal - Minimal subset of the Python language (version 2.7) Changes: python2.7 (2.7.13-2+deb9u4) stretch-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-20907 fix for an infinite loop when opening a crafted tar file * CVE-2019-16056 Fix incorrect parsing of email addresses with multiple '@' characters. * CVE-2019-10160 Fixes regression in fix for CVE-2019-9636 * CVE-2019-9948 Stop urllib exposing the local_file schema (file://). * CVE-2019-9740, CVE-2019-9947 Disallow control chars in http URLS in urllib2.urlopen. * CVE-2019-9636 Fix mishandling of NFKC normalization in urlsplit * CVE-2019-5010 Fix NULL pointer dereference when using a specially crafted X509 certificate * CVE-2018-20852 Cookie handling could be tricked to steal cookies for other domains. Checksums-Sha1: 2ca7abf1f75524101b027332d7815fd28eca23b7 3529 python2.7_2.7.13-2+deb9u4.dsc dce2b862a30099ee48c19a7c34e2d7c2eeff5670 17076672 python2.7_2.7.13.orig.tar.gz 599f145ada33ca9a79256fc4a1f4ac125bf96c2e 296390 python2.7_2.7.13-2+deb9u4.diff.gz 3bc8ec55eb8f562ddc84b916628eb3a5441779ae 336122 idle-python2.7_2.7.13-2+deb9u4_all.deb 08a63d405f7643bf726c1b5cfb7b2ae5b195c3ef 4662330 libpython2.7-dbg_2.7.13-2+deb9u4_amd64.deb 0a017c4f83493c467df8e013d15a0c12aa3be198 28196762 libpython2.7-dev_2.7.13-2+deb9u4_amd64.deb baae0d566c4560255c92148763e0b59246dda8d5 389620 libpython2.7-minimal_2.7.13-2+deb9u4_amd64.deb 48aefdeea213f0d6ade777c4748157d77b92773d 1897368 libpython2.7-stdlib_2.7.13-2+deb9u4_amd64.deb 396b51ee53b82217b45177d2029ccc6fcf58753f 2102878 libpython2.7-testsuite_2.7.13-2+deb9u4_all.deb 248594d68bd79361b35f453efecacb010b9cc3c0 1071342 libpython2.7_2.7.13-2+deb9u4_amd64.deb 761cf68f53b1d8805658fe94392ab002a25805ec 7877198 python2.7-dbg_2.7.13-2+deb9u4_amd64.deb c2215e8204774891237a0ac0c2571a7aa822ac44 303588 python2.7-dev_2.7.13-2+deb9u4_amd64.deb d4f9c7880f26eb093727405e1e758d5f2cd324f8 4335078 python2.7-doc_2.7.13-2+deb9u4_all.deb 570a8547ce444d695d9f15b4727ed5d87e2a88a0 709850 python2.7-examples_2.7.13-2+deb9u4_all.deb 205dc098aa5e923af065458cfa18b918a358a5e2 1386316 python2.7-minimal_2.7.13-2+deb9u4_amd64.deb 8688b131b4745f86876cd81e0933a25e132663c2 14287 python2.7_2.7.13-2+deb9u4_amd64.buildinfo 589426a13cb51d07366df1f55a8d820e3164e2bc 285772 python2.7_2.7.13-2+deb9u4_amd64.deb Checksums-Sha256: e4f8b227d30ca0cae71bb1ae0e938788a89882299c03d558ee042d74e5ec80d6 3529 python2.7_2.7.13-2+deb9u4.dsc a4f05a0720ce0fd92626f0278b6b433eee9a6173ddf2bced7957dfb599a5ece1 17076672 python2.7_2.7.13.orig.tar.gz 87709d2c0db04eb19afbe3ef91914b9a3ff14e5e69bf661bd825a34baaee7a42 296390 python2.7_2.7.13-2+deb9u4.diff.gz daa749459d2ccefa2a3fe81331545c1bb6cb1d658bb2f8ebf329c694c5072603 336122 idle-python2.7_2.7.13-2+deb9u4_all.deb 8cb6eaa33bb6eee496675317c3d1e487e02e88bd86f235de9b22fdaaadcd7071 4662330 libpython2.7-dbg_2.7.13-2+deb9u4_amd64.deb efaa895d6458bda8f4756c75d3e902c0df4419ad3129802767297ed9dc64bf2a 28196762 libpython2.7-dev_2.7.13-2+deb9u4_amd64.deb afc6240b6187f4bab2a1975e9360c1013131be26147b090c56ce1b8509fc7172 389620 libpython2.7-minimal_2.7.13-2+deb9u4_amd64.deb f4f218568d68174c16d63e559d58ba3bdaf5441ccccbb72d42267af056723aa6 1897368 libpython2.7-stdlib_2.7.13-2+deb9u4_amd64.deb 1559759ec3cd44d481106a52f30d75d2749eb8dd80a84b596991c19acaf92278 2102878 libpython2.7-testsuite_2.7.13-2+deb9u4_all.deb 836d3344386e876a929bec7359963958f7cc51a7c84ac50ba11ad1fb8556cfe8 1071342 libpython2.7_2.7.13-2+deb9u4_amd64.deb a8b957abab0c2c11af4e4b8f58e467b6d4352f0d5a47a19113e345216592242f 7877198 python2.7-dbg_2.7.13-2+deb9u4_amd64.deb 9b51bcdaacf1a327bbfc7ef05251f02f1886f93b957b94cd3fa442023d4b1f86 303588 python2.7-dev_2.7.13-2+deb9u4_amd64.deb 7e6482f3ae269478387128ee3c9e77a2357ec6f6ef28e314ad6ce0a8309dcdee 4335078 python2.7-doc_2.7.13-2+deb9u4_all.deb 03d3b43568b0895393d1f5b1d62f38b6735d7975fc6e1622cfc2c030d710e6c1 709850 python2.7-examples_2.7.13-2+deb9u4_all.deb 92a39de5402622ff55f919c3ccf3d6a192aae985f5803b9ae26a000309197e27 1386316 python2.7-minimal_2.7.13-2+deb9u4_amd64.deb ff5c154c3a3b719b81af85fd82e80701d1fa905059a6cb275bc8fa7a3f29403b 14287 python2.7_2.7.13-2+deb9u4_amd64.buildinfo 64f2ffbad0fd06e42e4b9c8a1d22c09cbda7f1d08e5a56b03bf91d67da30e663 285772 python2.7_2.7.13-2+deb9u4_amd64.deb Files: 41d448f6c9afc537d6c91b484c178dfc 3529 python optional python2.7_2.7.13-2+deb9u4.dsc 17add4bf0ad0ec2f08e0cae6d205c700 17076672 python optional python2.7_2.7.13.orig.tar.gz c02bbc1bb0cd2c723661c20ee6a0475b 296390 python optional python2.7_2.7.13-2+deb9u4.diff.gz a6c34f2013eec3d2ad1ff6bb952d63c5 336122 python optional idle-python2.7_2.7.13-2+deb9u4_all.deb 682b160bc87617179948d6a983de6486 4662330 debug extra libpython2.7-dbg_2.7.13-2+deb9u4_amd64.deb f19999530d8b74c834958d3b4a98053c 28196762 libdevel optional libpython2.7-dev_2.7.13-2+deb9u4_amd64.deb 8e64ec36354c09525e7a0d04d7a8eee8 389620 python optional libpython2.7-minimal_2.7.13-2+deb9u4_amd64.deb 9bbdeee363a9b354dcb5a13d04727cf4 1897368 python optional libpython2.7-stdlib_2.7.13-2+deb9u4_amd64.deb b83335609c8c99297dcc78c10384651b 2102878 libdevel optional libpython2.7-testsuite_2.7.13-2+deb9u4_all.deb 86e3631487f9bacc74ad40f503f04b37 1071342 libs optional libpython2.7_2.7.13-2+deb9u4_amd64.deb 3ba316dc64013a36978d3b5695aa29be 7877198 debug extra python2.7-dbg_2.7.13-2+deb9u4_amd64.deb eb5177a1c9e814eda6da02f01a0f33d6 303588 python optional python2.7-dev_2.7.13-2+deb9u4_amd64.deb 3ef97bb1a28568a5fd859e41384e74a8 4335078 doc optional python2.7-doc_2.7.13-2+deb9u4_all.deb e32f74aed6a17c7ff8ee86f0954d81c3 709850 python optional python2.7-examples_2.7.13-2+deb9u4_all.deb a09b17521e655d5d10db149455eff42a 1386316 python optional python2.7-minimal_2.7.13-2+deb9u4_amd64.deb 46e1e24db09905e76b15015c3190b809 14287 python optional python2.7_2.7.13-2+deb9u4_amd64.buildinfo d6ef03ec4375d0e0f759158fe454565e 285772 python optional python2.7_2.7.13-2+deb9u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl9BIFVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR4SoEACNe0rPerl7ll0IhfCvGuxueYyT4SgP jQe8KpRuEiVN7kcxJ6Pq/2cpR1AQI2ofJ6sSfVB3mRE9nE/oW3sLavHvwM+n7IE1 WQqFuzMRvhoaC2zricXxqMCwODCBFViqRnZyUvbcdWLNxmMawl+q8fUMDppOCfyS 6YarsHz+KqE9d/NgP3uQZ2OJRy2YFYjmly9rF1nHZEFLMNHNKFggRNkkPyy1dHcg 1gvDPmQyWaBpm1jA4rRYBPCcr6d+eCvhusy3gkJVIIwvAoZYoe3q8fAyVNYeHEWm sEpQ7n1gv2p1Bb0YIspQPk44Qy9eD2WYqRhSdtv+PAjp/PdPvZpdxMXOnxTtHaIg QMwapmDnstwTUgag0Srv4ZxIlp53J9jC3HHuoiy6g3tT9obGf52xLfX2+yJ+QPOO Nsa44kLdPil47s7Nzc9Rb6P8RYXRAe+jcZPy7K3yoL4wJN7H1l75F5bsPMxJLQAv hSUfkLtGwWoXaPUdnbAZSmSCaVQYoeKrnqPVaUV8GXo9dXzdiL9DOPCEn8aZS9fj 9Pl2qonPW0LmfJd7/tbT8YedWP12gFfVm283uUENG61hSD9ye6rw5zmh3drA46Zg 5Gr5KV4jB0O4YVwi8+KUcLPNrp3ATx4MHJSUD+N8+Ox4wmSho3dG5Vpn75jPJzIY aeiZ6MNnFJQIrg== =9Ivg -----END PGP SIGNATURE-----