Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20120425163137.GF2798@kludge.henri.nerv.fi>
Date: Wed, 25 Apr 2012 19:31:37 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Request: Python 3.2/3.3 utf-16 decoder
 unicode_decode_call_errorhandler aligned_end is not updated

On Wed, Apr 25, 2012 at 12:50:55PM +0200, Florian Weimer wrote:
> * Kurt Seifried:
> 
> > Python 3.2/3.3 utf-16 decoder unicode_decode_call_errorhandler
> > aligned_end is not updated
> >
> > does not appear to affect Python 2.x
> 
> 3.1 seems to be affected as well (according to reproducer and commit
> log).

Yes it is. I confirmed this also with Debian 3.1.3-12+squeeze1

- Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.