[issue29591] Various security vulnerabilities in bundled expat

Christian Heimes report at bugs.python.org
Fri Feb 17 10:44:49 EST 2017


Christian Heimes added the comment:

CVE-2016-0718 and CVE-2016-4472 might be relevant for Python. CVE-2016-5300 and CVE-2012-6702 are irrelevant. As Victor already pointed out, Python seeds libexpat from a good CPRNG.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue29591>
_______________________________________


More information about the Python-bugs-list mailing list