The python-rdflib-tools package (tools for converting to and from RDF) had wrappers that could load Python modules from the current working directory, allowing code injection. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2861-1
The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because "python -m" appends the current directory in the python path. . Package : rdflib Version : 4.1.2-3+deb8u1 CVE ID : CVE-2019-7653 Debian Bug : #921751 The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because "python -m" appends the current directory in the python path. For Debian 8 "Jessie", this problem has been fixed in version 4.1.2-3+deb8u1. We recommend that you upgrade your rdflib packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An important patch for the rdflib library in Debian LTS resolves a problem with module loading in Python. Users are advised to update promptly.. Debian LTS Security Update, Python rdflib Tools, CLI Tools Security, Package Upgrade. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.