Subject: CVS commit: pkgsrc/security/py-cryptography
From: Thomas Klausner
Date: 2015-10-19 11:37:29
Message id: 20151019093729.3126798@cvs.netbsd.org

Log Message:
Update py-cryptography to 1.0.2:

1.0.2 - 2015-09-27
~~~~~~~~~~~~~~~~~~
* **SECURITY ISSUE**: The OpenSSL backend prior to 1.0.2 made extensive use
  of assertions to check response codes where our tests could not trigger a
  failure.  However, when Python is run with ``-O`` these asserts are optimized
  away.  If a user ran Python with this flag and got an invalid response code
  this could result in undefined behavior or worse. Accordingly, all response
  checks from the OpenSSL backend have been converted from ``assert``
  to a true function call. Credit **Emilia Käsper (Google Security Team)**
  for the report.

Files:
RevisionActionfile
1.31modifypkgsrc/security/py-cryptography/Makefile
1.22modifypkgsrc/security/py-cryptography/distinfo