Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:1689-1

Опубликовано: 26 июн. 2017
Источник: suse-cvrf

Описание

Security update for python-tablib

This update for python-tablib fixes the following issues:

  • CVE-2017-2810: The Databook loading functionality allowed command execution when important malicious data (boo#1044329)

Список пакетов

openSUSE Leap 42.2
python-tablib-0.10.0-6.3.1

Описание

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.


Затронутые продукты
openSUSE Leap 42.2:python-tablib-0.10.0-6.3.1

Ссылки