gh-102950: Implement PEP 706 – Filter for tarfile.extractall by encukou · Pull Request #102953 · python/cpython (original) (raw)

Conversation

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})

encukou

@encukou

@encukou

ethanfurman

eryksun

@encukou

@encukou

Thanks to Ethan for spotting these

@encukou

@encukou

hroncok

gpshead

hroncok

Comment on lines 2309 to 2311

@encukou encukou deleted the tarfile-dir-traversal-sqsq branch

April 24, 2023 08:58

encukou added a commit to encukou/cpython that referenced this pull request

Apr 25, 2023

@encukou

encukou added a commit that referenced this pull request

Apr 28, 2023

@encukou

@mcepl mcepl mentioned this pull request

May 3, 2023

encukou added a commit that referenced this pull request

May 10, 2023

@mcepl @encukou

…H-102953) (GH-104128)

Co-authored-by: Petr Viktorin encukou@gmail.com

ambv pushed a commit that referenced this pull request

May 15, 2023

@encukou

ambv pushed a commit that referenced this pull request

May 17, 2023

@encukou

carlosroman added a commit to DataDog/cpython that referenced this pull request

Jun 22, 2023

Co-authored-by: Benjamin Peterson benjamin@python.org

Co-authored-by: Ned Deily nad@python.org

(cherry picked from commit 30a6cc4)

Co-authored-by: Ned Deily nad@python.org Co-authored-by: HARSHA VARDHAN 75431678+Thunder-007@users.noreply.github.com

(cherry picked from commit 1cf3d78) (cherry picked from commit 88fe8d7)

Co-authored-by: Jeremy Paige ucodery@gmail.com Co-authored-by: Gregory P. Smith greg@krypto.org

(cherry picked from commit c22a55c)

Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com

(cherry picked from commit ea23271)

Co-authored-by: Owain Davies 116417456+OTheDev@users.noreply.github.com

(cherry picked from commit 4652182)

Co-authored-by: Oleg Iarygin oleg@arhadthedev.net Co-authored-by: Steve Dower steve.dower@microsoft.com

[3.8] pythongh-101981: Fix Ubuntu SSL tests with OpenSSL (3.1.0-beta1) CI issue (pythongh-102079)

[3.8] Avoid GHA CI macOS test_posix failure by using the appropriate macOS SDK.

Fixes CVE-2023-0286 (High) and a couple of Medium security issues. https://www.openssl.org/news/secadv/20230207.txt

Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Ned Deily nad@python.org

(cherry picked from commit 61479d4)

Co-authored-by: Blind4Basics 32236948+Blind4Basics@users.noreply.github.com Co-authored-by: C.A.M. Gerlach CAM.Gerlach@Gerlach.CAM Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com

(cherry picked from commit 89d9ff0)

Backport of c8c3956

(cherry picked from commit 0aeda29)

Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com

Do not expose the local server's on-disk location from SimpleHTTPRequestHandler when generating a directory index. (unnecessary information disclosure)

(cherry picked from commit c7c3a60)

Co-authored-by: Ethan Furman ethan@stoneleaf.us Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Jelle Zijlstra jelle.zijlstra@gmail.com

Co-authored-by: Tian Gao gaogaotiantian@hotmail.com

(cherry picked from commit ee26ca1)

Co-authored-by: Irit Katriel 1055913+iritkatriel@users.noreply.github.com

urllib.parse.urlsplit has already been respecting the WHATWG spec a bit pythonGH-25595.

This adds more sanitizing to respect the "Remove any leading C0 control or space from input" rule in response to CVE-2023-24329.

I simplified the docs by eliding the state of the world explanatory paragraph in this security release only backport. (people will see that in the mainline /3/ docs)

(cherry picked from commit d7f8a5f) (cherry picked from commit 2f630e1) (cherry picked from commit 610cc0a) (cherry picked from commit f48a96a)

Co-authored-by: Miss Islington (bot) 31488909+miss-islington@users.noreply.github.com Co-authored-by: Illia Volochii illia.volochii@gmail.com Co-authored-by: Gregory P. Smith [Google] greg@krypto.org

Upgrade builds to OpenSSL 1.1.1u.

Also updates _ssl_data_111.h from OpenSSL 1.1.1u, _ssl_data_300.h from 3.0.9.

Manual edits to the _ssl_data_300.h file prevent it from removing any existing definitions in case those exist in some peoples builds and were important (avoiding regressions during backporting).

(cherry picked from commit ede89af) (cherry picked from commit e15de14)

Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Ned Deily nad@python.org


Co-authored-by: Łukasz Langa lukasz@langa.pl Co-authored-by: Benjamin Peterson benjamin@python.org Co-authored-by: Ned Deily nad@python.org Co-authored-by: Miss Islington (bot) 31488909+miss-islington@users.noreply.github.com Co-authored-by: HARSHA VARDHAN 75431678+Thunder-007@users.noreply.github.com Co-authored-by: Gregory P. Smith greg@krypto.org Co-authored-by: Jeremy Paige ucodery@gmail.com Co-authored-by: Hugo van Kemenade hugovk@users.noreply.github.com Co-authored-by: Steve Dower steve.dower@python.org Co-authored-by: Owain Davies 116417456+OTheDev@users.noreply.github.com Co-authored-by: Éric earaujo@caravan.coop Co-authored-by: Oleg Iarygin oleg@arhadthedev.net Co-authored-by: Steve Dower steve.dower@microsoft.com Co-authored-by: Dong-hee Na donghee.na@python.org Co-authored-by: Blind4Basics 32236948+Blind4Basics@users.noreply.github.com Co-authored-by: C.A.M. Gerlach CAM.Gerlach@Gerlach.CAM Co-authored-by: Pradyun Gedam pradyunsg@gmail.com Co-authored-by: Petr Viktorin encukou@gmail.com Co-authored-by: Sam Carroll 70000253+samcarroll42@users.noreply.github.com Co-authored-by: Ethan Furman ethan@stoneleaf.us Co-authored-by: Jelle Zijlstra jelle.zijlstra@gmail.com Co-authored-by: Tian Gao gaogaotiantian@hotmail.com Co-authored-by: Irit Katriel 1055913+iritkatriel@users.noreply.github.com Co-authored-by: stratakis cstratak@redhat.com Co-authored-by: Illia Volochii illia.volochii@gmail.com

IlyasTalbi

This comment was marked as spam.

maxwell-k added a commit to maxwell-k/dotlocalslashbin that referenced this pull request

Jul 16, 2024

@maxwell-k