Skip to content

Releases: ActiveState/cpython

ActivePython Release 3.7.17.5

19 Sep 19:45
Compare
Choose a tag to compare

What's Changed

Security

Upgrade bundled libexpat to 2.6.3 to fix the following CVEs:

  • CVE-2024-28757 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

  • CVE-2024-45490 An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

  • CVE-2024-45491 An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

  • CVE-2024-45492 An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

ActiveState Release of Python 2.7.18.10

06 Sep 16:22
3e06fbb
Compare
Choose a tag to compare

ActiveState Release of Python 2.7.18.10

What's Changed

Security

Core and Builtins

Full Changelog: v2.7.18.9...v2.7.18.10

ActivePython Release 3.7.17.4

23 Jul 04:34
Compare
Choose a tag to compare

What's Changed

Full Changelog: v3.7.17.3...v3.7.17.4

AS Release v2.7.18.9

27 Jun 23:17
Compare
Choose a tag to compare

ActiveState Release of Python 2.7.18.9

What's Changed

Full Changelog: v2.7.18.8...v2.7.18.9

AS Release v2.7.18.8

28 Jun 05:09
24790e1
Compare
Choose a tag to compare

ActiveState release 2.7.18.8

What's Changed

Full Changelog: v2.7.18.7...v2.7.18.8

AS Release v3.7.17.3

21 Sep 20:33
Compare
Choose a tag to compare

Release of ActivePython 3.7.17.3

AS Release v3.7.17.2

09 Sep 00:11
Compare
Choose a tag to compare
AS Release v3.7.17.2

AS Release v3.7.17.1

18 Aug 22:36
Compare
Choose a tag to compare
AS Release v3.7.17.1

First CVE fix release from ActiveState

30 Sep 18:28
d0065ee
Compare
Choose a tag to compare

The first release from ActiveState which fixes CVE-2020-8492.