Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[3.10] bpo-44549: Update bzip2 to 1.0.8 in Windows builds to mitigate CVE-2016-3189 and CVE-2019-12900 (GH-31731) #31732

Merged
merged 1 commit into from Mar 7, 2022

Conversation

Copy link
Member

@zooba zooba commented Mar 7, 2022

@zooba zooba requested a review from as a code owner Mar 7, 2022
@zooba zooba changed the title bpo-44549: Update bzip2 to 1.0.8 in Windows builds to mitigate CVE-2016-3189 and CVE-2019-12900 (GH-31731) [3.10] bpo-44549: Update bzip2 to 1.0.8 in Windows builds to mitigate CVE-2016-3189 and CVE-2019-12900 (GH-31731) Mar 7, 2022
@bedevere-bot bedevere-bot added the type-security label Mar 7, 2022
@zooba zooba merged commit 58d576a into python:3.10 Mar 7, 2022
12 checks passed
@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Mar 7, 2022

Thanks @zooba for the PR 🌮🎉.. I'm working now to backport this PR to: 3.7, 3.8, 3.9.
🐍🍒🤖

@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Mar 7, 2022

Sorry @zooba, I had trouble checking out the 3.9 backport branch.
Please backport using cherry_picker on command line.
cherry_picker 58d576a43cb1800dd68f06a429d7d41f746a8c01 3.9

@zooba zooba deleted the bpo-44549-3.10 branch Mar 7, 2022
@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Mar 7, 2022

Sorry, @zooba, I could not cleanly backport this to 3.8 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker 58d576a43cb1800dd68f06a429d7d41f746a8c01 3.8

@miss-islington
Copy link
Contributor

@miss-islington miss-islington commented Mar 7, 2022

Sorry @zooba, I had trouble checking out the 3.7 backport branch.
Please backport using cherry_picker on command line.
cherry_picker 58d576a43cb1800dd68f06a429d7d41f746a8c01 3.7

zooba added a commit to zooba/cpython that referenced this issue Mar 7, 2022
zooba added a commit to zooba/cpython that referenced this issue Mar 7, 2022
@bedevere-bot
Copy link

@bedevere-bot bedevere-bot commented Mar 7, 2022

GH-31733 is a backport of this pull request to the 3.9 branch.

zooba added a commit to zooba/cpython that referenced this issue Mar 7, 2022
@bedevere-bot
Copy link

@bedevere-bot bedevere-bot commented Mar 7, 2022

GH-31734 is a backport of this pull request to the 3.8 branch.

@bedevere-bot
Copy link

@bedevere-bot bedevere-bot commented Mar 7, 2022

GH-31735 is a backport of this pull request to the 3.7 branch.

ned-deily pushed a commit that referenced this issue Mar 7, 2022
zooba added a commit that referenced this issue Mar 7, 2022
ambv pushed a commit that referenced this issue Mar 8, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants