Merge branch 'master' into el6
This commit is contained in:
commit
26e06947de
2 changed files with 45 additions and 2 deletions
|
|
@ -0,0 +1,36 @@
|
|||
From ca207acb4fdea344bb3a775d44aa0d9f59ad31a1 Mon Sep 17 00:00:00 2001
|
||||
From: Toshio Kuratomi <toshio@fedoraproject.org>
|
||||
Date: Mon, 15 Jul 2013 10:58:20 -0700
|
||||
Subject: [PATCH] fix for http://bugs.python.org/issue17980 in code backported
|
||||
from the python3 stdlib
|
||||
|
||||
---
|
||||
pip/backwardcompat/ssl_match_hostname.py | 10 +++++++++-
|
||||
1 file changed, 9 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/pip/backwardcompat/ssl_match_hostname.py b/pip/backwardcompat/ssl_match_hostname.py
|
||||
index 5707649..a6fadf4 100644
|
||||
--- a/pip/backwardcompat/ssl_match_hostname.py
|
||||
+++ b/pip/backwardcompat/ssl_match_hostname.py
|
||||
@@ -7,9 +7,17 @@ __version__ = '3.2a3'
|
||||
class CertificateError(ValueError):
|
||||
pass
|
||||
|
||||
-def _dnsname_to_pat(dn):
|
||||
+def _dnsname_to_pat(dn, max_wildcards=1):
|
||||
pats = []
|
||||
for frag in dn.split(r'.'):
|
||||
+ if frag.count('*') > max_wildcards:
|
||||
+ # Issue #17980: avoid denials of service by refusing more
|
||||
+ # than one wildcard per fragment. A survery of established
|
||||
+ # policy among SSL implementations showed it to be a
|
||||
+ # reasonable choice.
|
||||
+ raise CertificateError(
|
||||
+ "too many wildcards in certificate DNS name: " + repr(dn))
|
||||
+
|
||||
if frag == '*':
|
||||
# When '*' is a fragment by itself, it matches a non-empty dotless
|
||||
# fragment.
|
||||
--
|
||||
1.7.11.7
|
||||
|
||||
|
|
@ -9,13 +9,15 @@
|
|||
|
||||
Name: python-%{srcname}
|
||||
Version: 1.3.1
|
||||
Release: 3%{?dist}
|
||||
Release: 4%{?dist}
|
||||
Summary: A tool for installing and managing Python packages
|
||||
|
||||
Group: Development/Libraries
|
||||
License: MIT
|
||||
URL: http://www.pip-installer.org
|
||||
Source0: http://pypi.python.org/packages/source/p/pip/%{srcname}-%{version}.tar.gz
|
||||
# Sent to dstufft (upstream)
|
||||
Patch0: 0001-fix-for-http-bugs.python.org-issue17980-in-code-back.patch
|
||||
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
||||
|
||||
BuildArch: noarch
|
||||
|
|
@ -48,6 +50,8 @@ easy_installable should be pip-installable as well.
|
|||
|
||||
%prep
|
||||
%setup -q -n %{srcname}-%{version}
|
||||
%patch0 -p1
|
||||
|
||||
%{__sed} -i '1d' pip/__init__.py
|
||||
|
||||
%if 0%{?with_python3}
|
||||
|
|
@ -70,7 +74,7 @@ popd
|
|||
|
||||
%if 0%{?with_python3}
|
||||
pushd %{py3dir}
|
||||
%{__python3} setup.py install -O1 --skip-build --root %{buildroot}
|
||||
%{__python3} setup.py install --skip-build --root %{buildroot}
|
||||
|
||||
# Change the name of the python3 pip executable in order to not conflict with
|
||||
# the python2 executable
|
||||
|
|
@ -132,6 +136,9 @@ popd
|
|||
%endif # with_python3
|
||||
|
||||
%changelog
|
||||
* Tue Jul 16 2013 Toshio Kuratomi <toshio@fedoraproject.org> - 1.3.1-4
|
||||
- Fix for CVE 2013-2099
|
||||
|
||||
* Thu May 23 2013 Tim Flink <tflink@fedoraproject.org> - 1.3.1-3
|
||||
- undo python2 executable rename to python-pip. fixes #958377
|
||||
- fix summary to match upstream
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue