Описание
Security update for python-tablib
This update for python-tablib fixes the following issues:
- CVE-2017-2810: The Databook loading functionality allowed command execution when important malicious data (boo#1044329)
Список пакетов
openSUSE Leap 42.2
python-tablib-0.10.0-6.3.1
Ссылки
- E-Mail link for openSUSE-SU-2017:1689-1
- SUSE Security Ratings
Описание
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.
Затронутые продукты
openSUSE Leap 42.2:python-tablib-0.10.0-6.3.1
Ссылки
- CVE-2017-2810
- SUSE Bug 1044329