[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-17626Date: (C)2019-10-17   (M)2023-12-22


ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with 'DSA-4663

FEDORA-2020-d2fb999600
FEDORA-2020-f3e0ba2f79
GLSA-202007-35
RHSA-2020:0195
RHSA-2020:0197
RHSA-2020:0201
RHSA-2020:0230
USN-4273-1
https://lists.debian.org/debian-lts-announce/2020/02/msg00019.html
https://bitbucket.org/rptlab/reportlab/issues/199/eval-in-colorspy-leads-to-remote-code
https://bitbucket.org/rptlab/reportlab/src/default/CHANGES.md
openSUSE-SU-2020:0160

CWE    1
CWE-91
OVAL    16
oval:org.secpod.oval:def:503493
oval:org.secpod.oval:def:503496
oval:org.secpod.oval:def:503495
oval:org.secpod.oval:def:66512
...

© SecPod Technologies