Описание
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
python3.9 | fixed | 3.9.1~rc1-1 | package | |
python3.8 | fixed | 3.8.7~rc1-1 | package | |
python3.7 | removed | package | ||
python2.7 | removed | package | ||
pypy3 | fixed | 7.3.5+dfsg-2 | package |
Примечания
https://python-security.readthedocs.io/vuln/cjk-codec-download-eval.html
https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8 (master)
https://github.com/python/cpython/commit/a8bf44d04915f7366d9f8dfbf84822ac37a4bab3 (master)
https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794 (v3.9.1rc1)
https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33 (v3.8.7rc1)
https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9 (v3.7.10)
https://bugs.python.org/issue41944
Only affects the testsuite
EPSS
Связанные уязвимости
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
EPSS