Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-19450

Опубликовано: 20 сент. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

4.0.4-11
esm-apps/noble

not-affected

4.0.4-11
esm-infra/bionic

needs-triage

esm-infra/focal

not-affected

3.5.34-1ubuntu1.1
esm-infra/xenial

needs-triage

focal

not-affected

3.5.34-1ubuntu1.1
jammy

not-affected

3.6.8-1ubuntu0.1
lunar

not-affected

3.6.12-1ubuntu0.1
mantic

not-affected

4.0.4-11

Показывать по

EPSS

Процентиль: 91%
0.06429
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 2 года назад

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

CVSS3: 9.8
nvd
почти 2 года назад

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

CVSS3: 9.8
debian
почти 2 года назад

paraparser in ReportLab before 3.5.31 allows remote code execution bec ...

suse-cvrf
почти 2 года назад

Security update for python-reportlab

suse-cvrf
почти 2 года назад

Security update for python-reportlab

EPSS

Процентиль: 91%
0.06429
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2019-19450