Created attachment 171488 [details] VuXML entry for Pythons' vuln CVE-2016-5636 Looks like Python 3.5, 3.4 and 2.7 are vulnerable to CVE-2016-5636. * Upstream issue: http://bugs.python.org/issue26171 * CVE assignment: http://openwall.com/lists/oss-security/2016/06/16/1 Attached is a vuxml entry patch. Please check it, this is my first vuxml submission. I also have not checked the status/vulnerability of python32 and python33, I am listing the hereby given three versions since that's what the upstream reported and patched.
Remove accidental extra feedback request.
I'll take it
A commit references this bug: Author: rm Date: Fri Jun 17 17:03:58 UTC 2016 New revision: 417018 URL: https://svnweb.freebsd.org/changeset/ports/417018 Log: Document integer overflow in python's zipimport module PR: 210324 Submitted by: Vladimir Krstulja <vlad-fbsd@acheronmedia.com> Security: CVE-2016-5636 Changes: head/security/vuxml/vuln.xml
Committed, thank you!