Repository navigation
[security][CVE-2020-27619] Python testsuite calls eval() on content received via HTTP #86110
Description
Activity
As was reported by Florian Bruhin, Python testsuite calls eval() on content received via HTTP (in Lib/test/multibytecodec_support.py).
- added3.10 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of lifetestsTests in the Lib/test dirTests in the Lib/test dirtype-securityA security issueA security issue
on Oct 5, 2020 I wonder if I should request a CVE for this as well? Just to make sure the word gets out to distributions/organizations/etc. running the Python testsuite, given that we can't be sure it which contexts this happens (and as it could be exploited by e.g. spoofing a WiFi network or so).
I don't think that a CVE is justified.
I don't know anyone running the Python test suite on production. Only developers of Python itself run Python.
- changed the title
[-]Python testsuite calls eval() on content received via HTTP[/-][+][security] Python testsuite calls eval() on content received via HTTP[/+]on Oct 6, 2020 - changed the title
[-]Python testsuite calls eval() on content received via HTTP[/-][+][security] Python testsuite calls eval() on content received via HTTP[/+]on Oct 6, 2020 12 remaining items
Thanks for the fix Serhiy and thanks Florian Bruhin for the bug report!
The CVE-2020-27619 has been assigned to this issue.
- changed the title
[-][security] Python testsuite calls eval() on content received via HTTP[/-][+][security][CVE-2020-27619] Python testsuite calls eval() on content received via HTTP[/+]on Nov 4, 2020 - changed the title
[-][security] Python testsuite calls eval() on content received via HTTP[/-][+][security][CVE-2020-27619] Python testsuite calls eval() on content received via HTTP[/+]on Nov 4, 2020 Red Hat advisory: https://access.redhat.com/security/cve/CVE-2020-27619
@gvanrossum, is there anything else that needs to be done in this issue?
Whoops, didn’t mean to reopen. This has happened a few times — I look at an issue, maybe subscribe, and it gets reopened?
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: