]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
bpo-26657: Fix Windows directory traversal vulnerability with http.server (#782)...
authorVictor Stinner <victor.stinner@gmail.com>
Wed, 26 Jul 2017 04:06:18 +0000 (06:06 +0200)
committerNed Deily <nad@python.org>
Wed, 26 Jul 2017 04:06:18 +0000 (00:06 -0400)
commit7b92f9fa47df754b50c64aac84cf1c09693571af
treea248646734e441d2ce39a4aa1c89423be83dd1da
parent8e88f6b5e2a35ee458c161aa3f2b7f1f17fb45d1
bpo-26657: Fix Windows directory traversal vulnerability with http.server (#782) (#2860)

Based on patch by Philipp Hagemeister.  This fixes a regression caused by
revision f4377699fd47.

(cherry picked from commit d274b3f1f1e2d8811733fb952c9f18d7da3a376a)
(cherry picked from commit 6f6bc1da8aaae52664e7747e328d26eb59c0e74f)
Lib/http/server.py
Lib/test/test_httpservers.py
Misc/NEWS.d/next/Security/2017-07-11-22-07-03.bpo-26657.wvpzFD.rst [new file with mode: 0644]