Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-0195

Опубликовано: 22 янв. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-0195: python-reportlab security update (IMPORTANT)

[2.5-9.el7_7.1]

  • Do not eval strings passed to toColor
  • Resolves: #1788552

[2.5-9]

  • Mass rebuild 2014-01-24

[2.5-8]

  • Mass rebuild 2013-12-27

[2.5-7]

[2.5-6]

  • Add a dep on python-imaging to process images

[2.5-5]

[2.5-4]

[2.5-3]

[2.5-2]

  • Update to version 2.5 of reportlab.
  • Remove tabs in specfile.

[2.3-3]

[2.3-2]

  • Do not bundle fonts
  • Point the config to Fedora's font locations

[2.3-1]

  • Updated to 2.3
  • New version is no longer noarch.

[2.1-6]

[2.1-5]

[2.1-4]

  • Fix locations for Python 2.6

[2.1-3]

  • Rebuild for Python 2.6

[2.1-2]

  • Remove luxi font. (#427845)
  • Add patch to not search for the luxi font.

[2.1-1]

  • Update to 2.1.

[2.0-2]

  • Make docs subpackage.

[2.0-1]

  • Update to 2.0.

[1.21.1-2]

  • Rebuild against new python.

[1.21.1-1]

  • Update to 1.20.1.

[1.20-5]

  • rebuilt for new gcc4.1 snapshot and glibc changes

[1.20-4]

  • Add dist tag. (#176479)

[1.20-3.fc4]

  • Switchback to sitelib patch.
  • Make package noarch.

[1.20-2.fc4]

  • Use python_sitearch to fix x86_64 build.

[1.20-1.fc4]

  • Rebuild for Python 2.4.
  • Update to 1.20.
  • Switch to the new python macros for python-abi
  • Add dist tag.

[0:1.19-0.fdr.2]

  • Removed ghosts.

[0:1.19-0.fdr.1]

  • Initial Fedora RPM build.

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

python-reportlab

2.5-9.el7_7.1

python-reportlab-docs

2.5-9.el7_7.1

Oracle Linux x86_64

python-reportlab

2.5-9.el7_7.1

python-reportlab-docs

2.5-9.el7_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

CVSS3: 9.8
redhat
больше 6 лет назад

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

CVSS3: 9.8
nvd
больше 6 лет назад

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.

CVSS3: 9.8
debian
больше 6 лет назад

ReportLab through 3.5.26 allows remote code execution because of toCol ...

suse-cvrf
около 6 лет назад

Security update for python-reportlab