Article 5EM5P [$] A pair of Python vulnerabilities

[$] A pair of Python vulnerabilities

by
jake
from LWN.net on (#5EM5P)
Two separate vulnerabilities led to the fast-tracked releaseof Python 3.9.2 and 3.8.8 on February 19, though source-onlyreleases of 3.7.10 and 3.6.13 came a few days earlier. Thevulnerabilities may be problematic for some Python users andworkloads; one could potentially lead to remote code execution. The otheris, arguably, not exactly a flaw in the Python standard library-it simplyalso follows an older standard-but it can lead to web cachepoisoning attacks.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments