Python 3.8.5 Update Addressing Vulnerabilities

Published a corrective update for the Python programming language 3.8.5, in which resolved several vulnerabilities:

  • CVE-2019-20907 — an infinite loop in the tarfile module when attempting to open specially crafted tar files.
  • BPO-41288 — a crash when the Pickle module tries to process objects with a specially crafted NEWOBJ_EX opcode.
  • CVE-2020-15801 — the possibility of injecting HTTP headers into a request by using newline characters in the 'method' parameter of the http.client module. For example: conn.request(method="GET / HTTP/1.1\r\nHost: abc\r\nRemainder:", url="/index.html"). This vulnerability was previously addressed but did not cover protection for the http.client.putrequest method.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster