Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia: 2021-0327 Moderate Severity: Python CJK Codec Eval Risk

mageia
Calendar Grey July 10, 2021
Dist Mageia Esm H88
The latest updates to the Python package enhance security by rectifying an issue in the CJK codec tests that previously utilized eval() on HTTP responses.
Updated python packages fix security vulnerability: In Python's Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP (CVE-2020-27619)

Summary

Updated python packages fix security vulnerability:
In Python's Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP (CVE-2020-27619).

References

- https://bugs.mageia.org/show_bug.cgi?id=29042

- https://bugzilla.redhat.com/show_bug.cgi?id=1889886

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/

- https://www.cve.org/CVERecord?id=CVE-2020-27619

Resolution

SRPMS

- 8/core/python-2.7.18-7.2.mga8

- 7/core/python-2.7.18-1.4.mga7

Publication date: 10 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0327.html
Type: security
CVE: CVE-2020-27619

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here