cusboonaysiinta Python 3.8.5 oo leh baylahda go'an

La daabacay cusboonaysiinta saxda ah ee luuqadda barnaamijka Python 3.8.5, kaas oo meesha laga saaray nuglaanta dhowr ah:

  • CVE-2019-20907 - module tarfile looping markii la isku dayayo in la furo faylal si gaar ah loo qaabeeyey oo qaab daamur ah.
  • BPO-41288 - shil markii moduleka Pickle uu isku dayo inuu walxaha ku farsameeyo opcode NEWOBJ_EX si gaar ah loo habeeyay.
  • CVE-2020-15801 - kartida loogu beddelo madax HTTP codsi iyada oo la adeegsanayo xarfaha khadka cusub ee "habka" cabbirka qaybta http.client. Tusaale ahaan: conn.request (hab = "GET / HTTP/1.1 \ r \ n Host: abc \ r \ n Remainder:", url = "/index.html"). Nuglaanta mar hore ayaa go'an, laakiin ma aysan daboolin amniga habka http.client.putrequest.

Source: opennet.ru

Add a comment