Joined: 12 May 2004
|Posted: Tue Jul 28, 2020 9:26 am Post subject: [ GLSA 202007-35 ] ReportLab
|Gentoo Linux Security Advisory
Title: ReportLab: Arbitrary code execution (GLSA 202007-35)
A vulnerability allowing arbitrary code execution was found in
ReportLab is an Open Source Python library for generating PDFs and
Vulnerable: < 3.5.42
Unaffected: >= 3.5.42
Architectures: All supported architectures
ReportLab was found to be mishandling XML documents and may evaluate the
contents without checking for their safety.
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause a Denial of Service condition.
There is no known workaround at this time.
All ReportLab users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-python/reportlab-3.5.42"