-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 19 Sep 2023 09:10:59 +0200 Source: python2.7 Architecture: source Version: 2.7.18-8+deb11u1 Distribution: bullseye Urgency: medium Maintainer: Matthias Klose <doko@debian.org> Changed-By: Helmut Grohne <helmut@subdivi.de> Changes: python2.7 (2.7.18-8+deb11u1) bullseye; urgency=medium . * Non-maintainer upload by the LTS Team. * Add testsuite-fix-with-expat.diff: Fix autopkgtests with updated expat. * Fix issue9189.diff: Update test suite to match behaviour change. * Add CVE-2021-23336.diff: Only use '&' as query string separator * Add CVE-2022-0391.diff: Make urlsplit robust against newlines * Add CVE-2022-48560.diff: Fix use-after-free in heapq module. * Add CVE-2022-48565.diff: Reject entities declarations while parsing XML plists. * Add CVE-2022-48566.diff: Make constant time comparison more constant-time. * Add CVE-2023-24329.diff: More WHATWG-compatible URL parsing * Add CVE-2023-40217.diff: Prevent reading unauthenticated data on a SSLSocket Checksums-Sha1: 7f958c4e1c74a262edd9c468f6bc695832bb3e69 3320 python2.7_2.7.18-8+deb11u1.dsc 24ff67cc0a790d852dc8f060c84be27d0321492d 317001 python2.7_2.7.18-8+deb11u1.diff.gz c8bec528d19a1106fc6945d26a40f06ca5463eb4 14782 python2.7_2.7.18-8+deb11u1_amd64.buildinfo Checksums-Sha256: fe0dda6d887e9e8133a7eb2b1fe2c75de81384a40eab188e20d99439d1302fd5 3320 python2.7_2.7.18-8+deb11u1.dsc 920b54018bc1b807077778be900157cf0a786621f4f7d7f69ec2096ff5d63f8e 317001 python2.7_2.7.18-8+deb11u1.diff.gz a99853cfd23d93c11bdbc8ae0ab974a1f4eee5e51b024d3320b11dfeb15851ae 14782 python2.7_2.7.18-8+deb11u1_amd64.buildinfo Files: c56d130e103225d27183db5b77d6e12f 3320 python optional python2.7_2.7.18-8+deb11u1.dsc 45d42026c10acf93dd944e7dfc5a6e01 317001 python optional python2.7_2.7.18-8+deb11u1.diff.gz af6eb93de722d4b8b93f9682b5b7f043 14782 python optional python2.7_2.7.18-8+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETMLS2QqNFlTb+HOqLRqqzyREREIFAmUQlmMACgkQLRqqzyRE REJCgA//XkscP7sP/sLybE7b0Cn5z+mjyP41fPKiPTLzCDRHkjHlWDykOQKUQWTW VQ7d0qV2RRob/EQDQ86SjSH+2rh3RDdff68Ty4fyGRMxOpcDpj03QNmd/xyc4IuZ jC63w7xOGI9M6ShSVfDmPqVypwT7SnnMKgLecZlgVTnoQ3uJ1vbxmyGIuQzLW/72 dRyhd7Yh+OxhVq7DsetYrULzfuk4mY5OmN9z1ZvpXICViFgEoxkZvt6rrmO1Xrb9 WV0rdR7uiRQHSGs6wtKYikUyov/6yPJ/mVlT4Weg6mQVPWh7TMc4JwSZ+qRc5ScE y1WD93R+ZJQiQquITY9JuCRE6XCiPmKCeja2Wb5ocoaCv5nLK2BtO+oc0Cd4q1d/ df63xf4pHogbQq8E2ttE5QvU1NQ+vSoh+TUI+nF1hX6uopmYiMCuQX21V8vFTMXd EMxONh2PvVL1uFvEI7+5Sch2eZ2PEFZtiJYs+U630BpLUav9tj0qZJVHDpV5ykVb D0hlk58tjDk41/93tNl4VUjXyC7xOZTiOpJN9VTA3SbOrGJp3JIO3jSxusQxcIPB Vm3250AajjPW4DCWu6XsV6UEDkUWJ/fhZk71cmK4MKrg/WLYlWQziIHUn/Cr9ec3 4J59RCoj6TsxS5s7wsGmI4OOX7bzKgD4VWzHTG28ev+sYFktnC8= =bLsW -----END PGP SIGNATURE-----