diff --git a/Misc/NEWS b/Misc/NEWS index e8efa0e81cb..f276cb3a138 100644 --- a/Misc/NEWS +++ b/Misc/NEWS @@ -139,6 +139,9 @@ Library - Issue #11666: let help() display named tuple attributes and methods that start with a leading underscore. +- Issue #11662: Make urllib and urllib2 ignore redirections if the + scheme is not HTTP, HTTPS or FTP (CVE-2011-1521). + - Issue #5537: Fix time2isoz() and time2netscape() functions of httplib.cookiejar for expiration year greater than 2038 on 32-bit systems.