Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Mageia 7: MGASA-2020-0477 Critical: Python3 Eval Remote Code Execution

mageia
Calendar Grey December 29, 2020
Dist Mageia Esm H88
The latest python3 updates in Mageia tackle a significant security vulnerability highlighted in CVE-2020-27619, which was announced on December 29, 2020.
In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP (CVE-2020-27619)

Summary

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP (CVE-2020-27619).

References

- https://bugs.mageia.org/show_bug.cgi?id=27868

- https://lists.suse.com/pipermail/sle-security-updates/2020-December/008081.html

- https://www.cve.org/CVERecord?id=CVE-2020-27619

Resolution

SRPMS

- 7/core/python3-3.7.9-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 29 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0477.html
Type: security
CVE: CVE-2020-27619

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here