Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

"I have five dollars for each of you." -- Bernhard Goetz


devel / comp.lang.python / Canonical list of Python security vulnerabilities

SubjectAuthor
o Canonical list of Python security vulnerabilitiesBob Kline

1
Canonical list of Python security vulnerabilities

<mailman.171.1689358289.23016.python-list@python.org>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=28189&group=comp.lang.python#28189

  copy link   Newsgroups: comp.lang.python
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!not-for-mail
From: bkline@rksystems.com (Bob Kline)
Newsgroups: comp.lang.python
Subject: Canonical list of Python security vulnerabilities
Date: Fri, 14 Jul 2023 13:35:35 -0400
Lines: 15
Message-ID: <mailman.171.1689358289.23016.python-list@python.org>
References: <CAGjKmVqN+nhH=3BR3VpmeW85hMqQdqQcv31kRFP_SsyFezuC=Q@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
X-Trace: news.uni-berlin.de yoPG43PDdO7TGR91OClhmwjJvjtNkSpIKsJBxUDIFYVA==
Cancel-Lock: sha1:VWlhS1NUaoLSq1W0DiZj1joikRE= sha256:bWqTsC7MyRnvu059EfxJ8lnRhnVygwcUbH9MGhgS4zg=
Return-Path: <bkline@rksystems.com>
X-Original-To: python-list@python.org
Delivered-To: python-list@mail.python.org
Authentication-Results: mail.python.org; dkim=pass
reason="2048-bit key; unprotected key"
header.d=rksystems-com.20221208.gappssmtp.com
header.i=@rksystems-com.20221208.gappssmtp.com
header.b=j2Z3CrIl; dkim-adsp=none (unprotected policy);
dkim-atps=neutral
X-Spam-Status: OK 0.009
X-Spam-Evidence: '*H*': 0.98; '*S*': 0.00; 'python.org.': 0.05;
'advise.': 0.09; "hasn't": 0.09; 'url-ip:151.101.0.223/32': 0.09;
'url-ip:151.101.128.223/32': 0.09; 'url-ip:151.101.192.223/32':
0.09; 'url-ip:151.101.64.223/32': 0.09; 'url-ip:45.79/16': 0.09;
'subject:list': 0.11; 'subject:Python': 0.12; 'bob': 0.16;
'cpython': 0.16; 'subject:skip:v 10': 0.16; 'python': 0.16;
'to:addr:python-list': 0.20; 'anything': 0.25; "isn't": 0.27;
'official': 0.32; 'message-id:@mail.gmail.com': 0.32; 'but': 0.32;
'there': 0.33; 'someone': 0.34; 'mean': 0.34;
'received:google.com': 0.34; 'year': 0.36; "it's": 0.37;
"there's": 0.61; 'url-ip:151.101.0/24': 0.62; 'url-
ip:151.101.128/24': 0.62; 'url-ip:151.101.192/24': 0.62; 'url-
ip:151.101.64/24': 0.62; 'security': 0.64; 'url-ip:45/8': 0.65;
'url-ip:104.18/16': 0.67; 'email addr:python.org,': 0.81; 'ask,':
0.84
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=rksystems-com.20221208.gappssmtp.com; s=20221208; t=1689356149; x=1691948149;
h=to:subject:message-id:date:from:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=/UnFkKgBhc5gp9QuXMjPHFNY3i66LMj3jTXm60VMmaI=;
b=j2Z3CrIlQbrmW/DsprUrQme8bIsHLXqKtlBiEb9GsHZlbW4gFUCc3CQrD4lIbW/E2P
4z56/FSwLE8WyijzGkaU+oYNzW5ennfvgqqwXEb8nE3XFuqboC1GkMcYKAgf46eoc5xt
mEZGG7vI1NKvUfJRFWqyn4+lTBzpWIY2MplmPtPx3tbT3bOQd6vFoSRVEbBydpuaGkm8
5r0oI2MKWnLw1O7YlldWrI9ZTVzyzPJHz/zArujOTqNy7ybXKhmCakQQczh0j7D7H6OU
WqxEGIL5V5VCC9RfNiDRQAlcTM1r1U31XBSz/J++6m+LQqg2ctdIiFoTnI15e5U11NWo
HWiQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20221208; t=1689356149; x=1691948149;
h=to:subject:message-id:date:from:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=/UnFkKgBhc5gp9QuXMjPHFNY3i66LMj3jTXm60VMmaI=;
b=Tf1HHInlcbt6u5kShRPIZYG56oHz7Gfti07sjYKKjsxRkJLGZvEbv0WBtXkj7iDaMZ
RKfAyAF9RWx2ptfbZi/cQMEeKtOUvdwQNs9fRHWpqzp2jmwoFq/3DYRqz9tylGQfIHfh
WctBHq7qe5H6d8D9trBCNQbCST8JgZD7Jqfu7WPDADxzHl1JsP11Glf+ckcFoBRScN2S
geHkoUAaCFoIoTwFGH1OlTR0GJanS3vLzx4G76LQTgH7TXzuYReXEh7QCBo9wzhTTHDM
LHMZNSybNhdIdIpCPzM52EJETy+DGn3nBq5IVMJcrzozCKBs4/rmTmmyoOhutPmTj2XU
/lcw==
X-Gm-Message-State: ABy/qLZYiG0U9bhppnP88cl2DhTTlKDBLWQL5SSgPUwpNPrl3i9mavir
bUy1MrvzTBMbkdFlNu9NyLV5aawuHMDjxa9KwGc5iiW9KZk3ORz3J71T8w==
X-Google-Smtp-Source: APBJJlGGW2VdPJ+beobjZcCphlVlAUfYIZeAZ11vXiV2kARV3VUq/xdoy5QN5Z3pinyky3uW6ZYha9Lxi+Kb8442gag=
X-Received: by 2002:a81:6306:0:b0:57a:3dd8:1038 with SMTP id
x6-20020a816306000000b0057a3dd81038mr6202482ywb.12.1689356148607; Fri, 14 Jul
2023 10:35:48 -0700 (PDT)
X-Mailman-Approved-At: Fri, 14 Jul 2023 14:11:28 -0400
X-Content-Filtered-By: Mailman/MimeDel 2.1.39
X-BeenThere: python-list@python.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: General discussion list for the Python programming language
<python-list.python.org>
List-Unsubscribe: <https://mail.python.org/mailman/options/python-list>,
<mailto:python-list-request@python.org?subject=unsubscribe>
List-Archive: <https://mail.python.org/pipermail/python-list/>
List-Post: <mailto:python-list@python.org>
List-Help: <mailto:python-list-request@python.org?subject=help>
List-Subscribe: <https://mail.python.org/mailman/listinfo/python-list>,
<mailto:python-list-request@python.org?subject=subscribe>
X-Mailman-Original-Message-ID: <CAGjKmVqN+nhH=3BR3VpmeW85hMqQdqQcv31kRFP_SsyFezuC=Q@mail.gmail.com>
 by: Bob Kline - Fri, 14 Jul 2023 17:35 UTC

Can someone point me to the official catalog of security vulnerabilities in
Python (by which I mean cpython and the standard libraries)? I found
https://www.cvedetails.com/vulnerability-list/vendor_id-10210/product_id-18230/Python-Python.html
but that isn't maintained by python.org. I also found
security-announce@python.org, but there hasn't been anything posted there
in over a year as far as I can tell, and even before that it's pretty thin.

If there's a better place to ask, please advise.

Thanks.

--
Bob Kline
https://www.rksystems.com
mailto:bkline@rksystems.com


devel / comp.lang.python / Canonical list of Python security vulnerabilities

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor