python-reportlab: code injection in colors.py allows attacker to execute code
Published Oct 16, 2019
9.3
CRITICALCVSS 4.0
EPSS 10.23%
Description
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
Affected products
No data.
-
- Version 0StatusaffectedConstraints<=3.5.26
- Version
Red Hat Enterprise Linux 6
python-reportlab-0:2.3-3.el6_10.1
Fixed · RHSA-2020:0197
Red Hat Enterprise Linux 7
python-reportlab-0:2.5-9.el7_7.1
Fixed · RHSA-2020:0195
Red Hat Enterprise Linux 8
python-reportlab-0:3.4.0-6.el8_1.2
Fixed · RHSA-2020:0201
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
python-reportlab-0:3.4.0-6.el8_0.2
Fixed · RHSA-2020:0230
Red Hat Quay 3
quay
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | python-reportlab-0:2.3-3.el6_10.1 | Fixed | RHSA-2020:0197 |
| Red Hat Enterprise Linux 7 | python-reportlab-0:2.5-9.el7_7.1 | Fixed | RHSA-2020:0195 |
| Red Hat Enterprise Linux 8 | python-reportlab-0:3.4.0-6.el8_1.2 | Fixed | RHSA-2020:0201 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | python-reportlab-0:3.4.0-6.el8_0.2 | Fixed | RHSA-2020:0230 |
| Red Hat Quay 3 | quay | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability will not be fixed in Red Hat Quay because it only affects a non-supported feature which is disabled behind a feature flag.
Red Hat mitigation
No known mitigation available.
References (26)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00002.html vendor-advisory
- https://access.redhat.com/errata/RHSA-2020:0195 vendor-advisory
- https://access.redhat.com/errata/RHSA-2020:0197 vendor-advisory
- https://access.redhat.com/errata/RHSA-2020:0201 vendor-advisory
- https://access.redhat.com/errata/RHSA-2020:0230 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2019-17626 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2019-17626
- https://bitbucket.org/rptlab/reportlab/issues/199/eval-in-colorspy-leads-to-remote-code ExploitIssue TrackingThird Party Advisory
- https://bitbucket.org/rptlab/reportlab/src/default/CHANGES.md Release NotesThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1769661 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0122 Advisory
- https://github.com/advisories/GHSA-qpg2-vx7j-3869 Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/reportlab/PYSEC-2019-117.yaml
- https://hg.reportlab.com/hg-public/reportlab/rev/51a521ad7dd3
- https://lists.debian.org/debian-lts-announce/2020/02/msg00019.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NSCTOE3DITFICY2XKBYZ5WAF5TSQ52DM vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZZPHP2BJSTP4IYCSJRQINP763IHO6ASL vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NSCTOE3DITFICY2XKBYZ5WAF5TSQ52DM
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZPHP2BJSTP4IYCSJRQINP763IHO6ASL
- https://nvd.nist.gov/vuln/detail/CVE-2019-17626
- https://security.gentoo.org/glsa/202007-35 vendor-advisory
- https://security.netapp.com/advisory/ntap-20240719-0006
- https://usn.ubuntu.com/4273-1 vendor-advisory
- https://web.archive.org/web/20191016111823/https://bitbucket.org/rptlab/reportlab/issues/199/eval-in-colorspy-leads-to-remote-code
- https://www.cve.org/CVERecord?id=CVE-2019-17626
- https://www.debian.org/security/2020/dsa-4663 vendor-advisory
Change history (0)
No recorded changes yet.