Python 3.8.5 update ine vulnerabilities yakagadziriswa

Yakabudiswa pa kugadzirisa kugadzirisa kwePython 3.8.5 programming mutauro, umo kubviswa kusasimba kwakawanda:

  • CVE-2019-20907 - tarfile module looping paunenge uchiedza kuvhura mafaira akagadzirwa mune tar fomati.
  • BPO-41288 - Kuparara kana Pickle module ichiedza kugadzirisa zvinhu neopcode yakagadzirwa NENEWOBJ_EX.
  • CVE-2020-15801 - kugona kutsiva misoro yeHTTP muchikumbiro kuburikidza nekushandisa mavara matsva mu "method" parameter ye http.client module. Semuenzaniso: conn.request(method=”GET / HTTP/1.1\r\nHost: abc\r\nRemainder:”, url=”/index.html”). Dambudziko rakambogadziriswa, asi harina kuvhara http.client.putrequest nzira yekuchengetedza.

Source: opennet.ru

Voeg