Python 3.8.5 nganyari karo vulnerabilities tetep

Diterbitake ing nganyari mbenakake Python 3.8.5 programming language, kang diilangi sawetara kerentanan:

  • CVE-2019-20907 - modul tarfile looping nalika nyoba mbukak file sing dirancang khusus ing format tar.
  • BPO-41288 - kacilakan nalika modul Pickle nyoba kanggo proses obyek karo opcode dirancang khusus NEWOBJ_EX.
  • CVE-2020-15801 - kemampuan kanggo ngganti header HTTP menyang panjalukan liwat nggunakake karakter baris anyar ing parameter "metode" modul http.client. Contone: conn.request(method=”GET / HTTP/1.1\r\nHost: abc\r\nSisa:”, url=”/index.html”). Kerentanan kasebut sadurunge tetep, nanging ora nutupi keamanan metode http.client.putrequest.

Source: opennet.ru

Add a comment