GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Jul 28, 2020 9:26 am Post subject: [ GLSA 202007-35 ] ReportLab |
|
|
Gentoo Linux Security Advisory
Title: ReportLab: Arbitrary code execution (GLSA 202007-35)
Severity: normal
Exploitable: remote
Date: 2020-07-27
Bug(s): #710738
ID: 202007-35
Synopsis
A vulnerability allowing arbitrary code execution was found in
ReportLab.
Background
ReportLab is an Open Source Python library for generating PDFs and
graphics.
Affected Packages
Package: dev-python/reportlab
Vulnerable: < 3.5.42
Unaffected: >= 3.5.42
Architectures: All supported architectures
Description
ReportLab was found to be mishandling XML documents and may evaluate the
contents without checking for their safety.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All ReportLab users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-python/reportlab-3.5.42"
|
References
CVE-2019-17626 |
|