[Bug 1161562] New: VUL-1: CVE-2019-19274: python-typed-ast: out-of-bounds read may crash Python interpreter
http://bugzilla.opensuse.org/show_bug.cgi?id=1161562 Bug ID: 1161562 Summary: VUL-1: CVE-2019-19274: python-typed-ast: out-of-bounds read may crash Python interpreter Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: Other URL: https://smash.suse.de/issue/248003/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: sebix+novell.com@sebix.at Reporter: atoptsoglou@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2019-19274 typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.) References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-19274 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-19274.html https://github.com/python/cpython/commit/a4d78362397fc3bced6ea80fbc7b5f4827a... https://github.com/python/cpython/commit/dcfcd146f8e6fc5c2fc16a4c192a0c5f5ca... https://github.com/python/typed_ast/commit/156afcb26c198e162504a57caddfe0acd... https://github.com/python/typed_ast/commit/dc317ac9cff859aa84eeabe03fb500498... http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19274 https://bugs.python.org/issue36495 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1161562 http://bugzilla.opensuse.org/show_bug.cgi?id=1161562#c1 Sebastian Wagner <sebix+novell.com@sebix.at> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS CC| |sebix+novell.com@sebix.at --- Comment #1 from Sebastian Wagner <sebix+novell.com@sebix.at> --- http://build.opensuse.org/request/show/769259 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1161562 http://bugzilla.opensuse.org/show_bug.cgi?id=1161562#c2 Sebastian Wagner <sebix+novell.com@sebix.at> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |FEATURE --- Comment #2 from Sebastian Wagner <sebix+novell.com@sebix.at> --- Request got accepted -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1161562 Sebastian Wagner <sebix+novell.com@sebix.at> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|FEATURE |FIXED -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com