[issue21671] CVE-2014-0224: OpenSSL upgrade to 1.0.1h on Windows required

Steve Dower report at bugs.python.org
Sun Jun 8 21:02:57 CEST 2014


Steve Dower added the comment:

The only reason to do it is to help out those who build from source, which I suspect is an incredibly small group on Windows. We'd also be signing up to keep doing it, and implying that it's been tested.

I say don't bother.
________________________________
From: Zachary Ware<mailto:report at bugs.python.org>
Sent: ‎6/‎8/‎2014 11:57
To: Steve Dower<mailto:Steve.Dower at microsoft.com>
Subject: [issue21671] CVE-2014-0224: OpenSSL upgrade to 1.0.1h on Windows required

Zachary Ware added the comment:

So installers are out for 3.1-3.3; should we still update the externals script and pyproject properties for those branches anyway?  If not, this issue should be ready to close.

----------
stage:  -> commit review
status: open -> pending
type:  -> security

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue21671>
_______________________________________

----------
status: pending -> open

_______________________________________
Python tracker <report at bugs.python.org>
<http://bugs.python.org/issue21671>
_______________________________________


More information about the Python-bugs-list mailing list