-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 21 Dec 2025 23:37:54 +0100 Source: python-mechanize Architecture: source Version: 1:0.4.5-2+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Daniel Leidert <dleidert@debian.org> Changes: python-mechanize (1:0.4.5-2+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload by the Debian LTS Team. * d/patches/CVE-2021-32837.patch: Add patch to fix CVE-2021-32837. - Fix a regular expression denial of service (ReDoS). If a web server responds in a malicious way, then mechanize could crash. Checksums-Sha1: b107495c24ce77a7b152ec10eddf97a03ecb1650 2188 python-mechanize_0.4.5-2+deb11u1.dsc 186b19757c4c36031f1ffb36e37449439855d955 223647 python-mechanize_0.4.5.orig.tar.gz 4ee31cf9a2e058f519300bc11dc9986ae14fbf38 8696 python-mechanize_0.4.5-2+deb11u1.debian.tar.xz 8cf8e755e24452b439823fa191df62304868efe9 8490 python-mechanize_0.4.5-2+deb11u1_amd64.buildinfo Checksums-Sha256: ee361ac212f15b511d7344dbe624d9b5b9b37eec738266e2f3e53355cdf5a67f 2188 python-mechanize_0.4.5-2+deb11u1.dsc 08515f36d315566b256888bbe50e3587293397028c45b5289f3e38fede3c574f 223647 python-mechanize_0.4.5.orig.tar.gz 32625cbe4dad2d7ecc4acc7a9a3cd77e09e37da41805d22d8af094710bc1ad2e 8696 python-mechanize_0.4.5-2+deb11u1.debian.tar.xz c5b8434d1f150b200b4e3ab43bd4a0b6fffd86aac7b69ff3dccbc5edeb4eba99 8490 python-mechanize_0.4.5-2+deb11u1_amd64.buildinfo Files: cd9f4dd2a397731fd0f476d03af534f6 2188 python optional python-mechanize_0.4.5-2+deb11u1.dsc a3cfa9714d456ff20c73195bf7a75606 223647 python optional python-mechanize_0.4.5.orig.tar.gz 1b26df41a2342b7cdd86f6420e6b8934 8696 python optional python-mechanize_0.4.5-2+deb11u1.debian.tar.xz 706bca7cbc1e72eca66cc8cd06596a13 8490 python optional python-mechanize_0.4.5-2+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmlIf8YACgkQS80FZ8KW 0F0tBg//aZZJ8keqBP4O87ZKt827lb8LJlNyKiygbQNt4fZEL/DjykdSN7O0oEpw WLsQHP0DEwqt0kM7X08/MLRCt6SkG85ooyfoN/L+lV/N/IkpHiClaDyto8ZH/hTE gPmJfqSwT0BYGdNieWTgwsvyAVNNQCotFoVsl/aH1V9q7WoaTo6tE4SEJLKsgk8i tm3PwORsGYCKNGd1E5pZ1l2xDEvG4DSsToWzj/0nPJMaB+n81kfYwMYvDjCXzbHN RzrgIxGZVIEYDj3KZAI/DU7/d5tWf3qEs4lrFrT+dYmh+aatr+gHi1etHLfPgmWX wC+ANmDd1LILUarBXLmDkNY9LjSTMXyRD7ucv+K5cyal88eP3aUTTwl181RMYhEx 54i+9kbGzRU7C0HQkGrqJDBREpTUqQYcpmmM7+wqwGTrIdbG1NAUoEotsuIUq3oP 23jYssZGjgUNAPMarUKHIRXXHxIKuz3QkWfjYimL6rWJp5m/VmEVaiiV9RTZGYV2 0GkAhM03+4ypw8gXoxtk7PU5R2RYjmCwn7gjOEaN/Nyxx6ZG4In7QSm4z+LE/ZYv Savbtz3rkO5qmpz883MeWY6wzODsYgtZwMm6OC0DGAuqPddgIc6lwEdvmeYSDVvr Km20MvsHqVO3QyYyN4T0xOnJ0dpdfyBf957RZR18g31Daij7p0g= =JTyr -----END PGP SIGNATURE-----