Due to an error in the caching organization within the content delivery system, when attempting to download one of the builds the day before yesterday of the corrective release a beta build that did not contain all the fixes. The issue only the archive , the build was distributed correctly.
All users who downloaded the file 'Python-3.5.8.tar.xz' within the first 12 hours after the release are advised to verify the integrity of the downloaded data using the checksum (MD5 4464517ed6044bca4fc78ea9ed086c36). Unlike the final release, the preliminary version did not include a vulnerability in the XML-RPC server code. The vulnerability allowed for the injection of JavaScript code (XSS) through the server_title field due to the lack of escaping angle brackets. An attacker could achieve the injection of JavaScript code if the application set the server name based on user input (for example, 'server.set_server_name(‘test’)').
Source: opennet.ru
