Re: ANN: Critical security updates to Django 1.0 and Django 1.1

2009-10-18 Thread Stuart Jansen
On Sat, 2009-10-17 at 04:40 -0700, klas.hagg...@hotmail.com wrote: > How come the new regular expression allows TLDs to end with a '.' > character? For example 'n...@domain.com.' (note the period at the end) > is regarded as a valid email address. Perhaps because it is a valid domain name? http:

Re: ANN: Critical security updates to Django 1.0 and Django 1.1

2009-10-17 Thread klas.hagg...@hotmail.com
How come the new regular expression allows TLDs to end with a '.' character? For example 'n...@domain.com.' (note the period at the end) is regarded as a valid email address. --~--~-~--~~~---~--~~ You received this message because you are subscribed to the Google G

ANN: Critical security updates to Django 1.0 and Django 1.1

2009-10-09 Thread James Bennett
Today the Django project is issuing a set of releases to remedy a security issue. This issue was disclosed publicly by a third party on a high-traffic mailing list, and attempts have been made to exploit it against live Django installations; as such, we are bypassing our normal policy for security