Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6v3-hpxj-r8rv

Опубликовано: 07 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Code Injection in PyXDG

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

Пакеты

Наименование

pyxdg

pip
Затронутые версииВерсия исправления

< 0.26

0.26

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

CVSS3: 6.1
redhat
больше 6 лет назад

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

CVSS3: 7.5
nvd
больше 6 лет назад

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

CVSS3: 7.5
debian
больше 6 лет назад

A code injection issue was discovered in PyXDG before 0.26 via crafted ...

suse-cvrf
больше 3 лет назад

Security update for python-pyxdg

EPSS

Процентиль: 70%
0.00645
Низкий

7.5 High

CVSS3

Дефекты

CWE-94