python-reportlab-2.5-11.el7

エラータID: AXSA:2023-6484:01

Release date: 
Wednesday, October 11, 2023 - 00:56
Subject: 
python-reportlab-2.5-11.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Python-reportlab is a library used for generation of PDF documents.

Security Fix(es):

* python-reportlab: code injection in paraparser.py allows code execution (CVE-2019-19450)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-19450
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '

Solution: 

Update packages.