[issue29778] [CVE-2020-15523] _Py_CheckPython3 uses uninitialized dllpath when embedder sets module path with Py_SetPath

Steve Dower report at bugs.python.org
Tue Jul 7 12:08:25 EDT 2020


Steve Dower <steve.dower at python.org> added the comment:

> Python 3.5 is also vulnerable, no? This branch still gets security fixes, do you plan to backport the fix?

You're right. I thought because the backport tag was gone on GitHub that it was EOL already.

I can do the backport.

----------
nosy: +larry
versions: +Python 3.5

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue29778>
_______________________________________


More information about the Python-bugs-list mailing list