[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-19450Date: (C)2023-09-20   (M)2024-05-08


paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with 'FEDORA-2024-6ec4e78241

FEDORA-2024-dc844d0669
https://lists.debian.org/debian-lts-announce/2023/09/msg00037.html
https://github.com/MrBitBucket/reportlab-mirror/blob/master/CHANGES.md
https://pastebin.com/5MicRrr4

CWE    1
CWE-91
OVAL    9
oval:org.secpod.oval:def:3301967
oval:org.secpod.oval:def:206070
oval:org.secpod.oval:def:508196
oval:org.secpod.oval:def:508197
...

© SecPod Technologies