Uhlaziyo lwePython 3.8.5 kunye nobuthathaka obulungisiweyo

Papashwe ngomhla uhlaziyo olulungisayo lwePython 3.8.5 ulwimi lokuprograma, apho isusiwe Ubuthathaka obuninzi:

  • I-CVE-2019-20907 -Imodyuli yetarfile ejikelezayo xa uzama ukuvula iifayile eziyilwe ngokukodwa kwifomati yetar.
  • I-BPO-41288 β€” konakala xa imodyuli yePickle izama ukucubungula izinto nge-opcode eyilwe ngokukodwa NENEWOBJ_EX.
  • I-CVE-2020-15801 - ukukwazi ukufaka iiheader zeHTTP endaweni yesicelo ngokusetyenziswa kweempawu zomgca omtsha kwi-parameter "yendlela" ye-http.client module. Umzekelo: conn.request(indlela=”GET / HTTP/1.1\r\nHost: abc\r\nRemander:”, url=”/index.html”). Ubuthathaka bebulungisiwe ngaphambili, kodwa abuzange bugubungele indlela yokhuseleko ye-http.client.putrequest.

umthombo: opennet.ru

Yongeza izimvo