Python 3.8.5 hloov tshiab nrog vulnerabilities tsau

Luam tawm rau kho kho tshiab ntawm Python 3.8.5 programming lus, uas tshem tawm ob peb vulnerabilities:

  • CVE-2019-20907 - tarfile module looping thaum sim qhib cov ntaub ntawv tsim tshwj xeeb hauv tar hom.
  • PIB-41288 - tsoo thaum lub Pickle module sim ua cov khoom siv tshwj xeeb tsim opcode NEWOBJ_EX.
  • CVE-2020-15801 - lub peev xwm los hloov HTTP headers rau hauv qhov kev thov los ntawm kev siv cov cim tshiab hauv "txoj kev" parameter ntawm http.client module. Piv txwv li: conn.request(method=”GET / HTTP/1.1\r\nHost: abc\r\nRemainder:”, url=”/index.html”). Qhov tsis zoo tau raug kho yav tas los, tab sis tsis tau them rau http.client.putrequest txoj kev ruaj ntseg.

Tau qhov twg los: opennet.ru

Ntxiv ib saib