Hello, I've written a simple reproduction script for the CVE, which validates whether or not the issue is fixed.
You can find it at https://gist.github.com/OddBloke/211ff98b63a8cfb3f6d4; all you need installed is python-bottle (for HTTP serving). Dan
signature.asc
Description: OpenPGP digital signature