Isibuyekezo se-Python 3.8.5 esinokukhubazeka okulungisiwe

Kushicilelwe ku isibuyekezo sokulungisa solimi lokuhlela lwePython 3.8.5, lapho kuqedwe ubungozi obuningana:

  • I-CVE-2019-20907 - i-tarfile module looping lapho uzama ukuvula amafayela aklanywe ngokukhethekile ngefomethi ye-tar.
  • I-BPO-41288 β€” iphahlazeka lapho imojula ye-Pickle izama ukucubungula izinto nge-opcode eklanywe ngokukhethekile NEWOBJ_EX.
  • I-CVE-2020-15801 β€” ikhono lokushintsha izihloko ze-HTTP zibe isicelo ngokusebenzisa izinhlamvu zomugqa omusha kupharamitha β€œyendlela” yemojuli ye-http.client. Isibonelo: conn.request(indlela=”GET / HTTP/1.1\r\nHost: abc\r\nRemander:”, url=”/index.html”). Ukuba sengozini kwalungiswa ngaphambilini, kodwa akuzange kufake indlela yokuphepha ye-http.client.putrequest.

Source: opennet.ru

Engeza amazwana