Subject: CVS commit: pkgsrc/lang/python34
From: Adam Ciarcinski
Date: 2019-03-20 20:29:11
Message id: 20190320192911.B87C4FB16@cvs.NetBSD.org

Log Message:
python34: updated to 3.4.10

Python 3.4.10 final

Security
bpo-36216: Changes urlsplit() to raise ValueError when the URL contains \ 
characters that decompose under IDNA encoding (NFKC-normalization) into \ 
characters that affect how the URL is parsed.
bpo-35121: Don’t send cookies of domain A without Domain attribute to domain B \ 
when domain A is a suffix match of domain B while using a cookiejar with \ 
http.cookiejar.DefaultCookiePolicy policy.

Library
bpo-35121: Don’t set cookie for a request when the request path is a prefix \ 
match of the cookie’s path attribute but doesn’t end with “/”.

Python 3.4.10 release candidate 1

Security
bpo-35746: [CVE-2019-5010] Fix a NULL pointer deref in ssl module. The cert \ 
parser did not handle CRL distribution points with empty DP or URI correctly. A \ 
malicious or buggy certificate can result into segfault. Vulnerability \ 
(TALOS-2018-0758).
bpo-34791: The xml.sax and xml.dom.domreg no longer use environment variables to \ 
override parser implementations when sys.flags.ignore_environment is set by -E \ 
or -I arguments.
bpo-34623: CVE-2018-14647: The C accelerated _elementtree module now initializes \ 
hash randomization salt from _Py_HashSecret instead of libexpat’s default \ 
CSPRNG.

Library
bpo-33329: Fix multiprocessing regression on newer glibcs

Files:
RevisionActionfile
1.30modifypkgsrc/lang/python34/Makefile
1.11modifypkgsrc/lang/python34/PLIST
1.11modifypkgsrc/lang/python34/dist.mk
1.34modifypkgsrc/lang/python34/distinfo