[issue36384] [security] CVE-2021-29921: ipaddress Should not reject IPv4 addresses with leading zeroes as ambiguously octal

May 25, 2021
4:44 p.m.
STINNER Victor <vstinner@python.org> added the comment: George-Cristian Bîrzan: "The timeline there is wrong." Fixed: https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.htm... The strange part is "2019-03-20 (-741 days): Python issue bpo-36384 reported by Joel Croteau". The problem is that this issue was "reused" for two different things: the initial change and the vulnerability. Maybe I can removed the reference to the bpo to remove it from the timeline (and put it in links). ---------- _______________________________________ Python tracker <report@bugs.python.org> <https://bugs.python.org/issue36384> _______________________________________
1386
Age (days ago)
1386
Last active (days ago)
0 comments
1 participants
participants (1)
-
STINNER Victor