[issue46687] Update pyexpat for CVE-2021-45960

2022-02-09 Thread Steve Dower
Steve Dower added the comment: Probably. I searched for the CVE number and didn't find it anywhere, but that issue only mentions the new release version. -- resolution: -> duplicate stage: needs patch -> resolved status: open -> closed superseder: -> Please update bundled libexpat t

[issue46687] Update pyexpat for CVE-2021-45960

2022-02-08 Thread Ned Deily
Ned Deily added the comment: Duplicate of Issue46400 ? -- nosy: +ned.deily ___ Python tracker ___ ___ Python-bugs-list mailing list

[issue46687] Update pyexpat for CVE-2021-45960

2022-02-08 Thread Steve Dower
New submission from Steve Dower : libexpat recently fixed a security issue relating to some arithmetic: https://github.com/libexpat/libexpat/pull/534 I assume we should take this fix, either by updating our entire bundled copy or just backporting the patch. -- components: XML message