Skip to content

[3.8] [CVE-2023-27043] gh-102988: Reject malformed addresses in email.parseaddr() (GH-111116)#123770

Merged
ambv merged 2 commits intopython:3.8from
encukou:backport-4a153a1-3.8
Sep 6, 2024
Merged

[3.8] [CVE-2023-27043] gh-102988: Reject malformed addresses in email.parseaddr() (GH-111116)#123770
ambv merged 2 commits intopython:3.8from
encukou:backport-4a153a1-3.8

Conversation

@encukou
Copy link
Member

@encukou encukou commented Sep 6, 2024

vstinner and others added 2 commits September 6, 2024 12:53
… email.parseaddr() (pythonGH-111116)

Detect email address parsing errors and return empty tuple to
indicate the parsing error (old API). Add an optional 'strict'
parameter to getaddresses() and parseaddr() functions. Patch by
Thomas Dwyer.

(cherry picked from commit 4a153a1)

Co-authored-by: Victor Stinner <vstinner@python.org>
Co-Authored-By: Thomas Dwyer <github@tomd.tel>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-bug An unexpected behavior, bug, or error type-security A security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants