HIGH
python-reportlab: remote code execution via supplying a crafted PDF file
Published Jun 5, 2023
7.8
HIGHCVSS 3.1
EPSS 2.12%
Description
Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
python-reportlab
Not affected
Red Hat Enterprise Linux 7
python-reportlab
Not affected
Red Hat Enterprise Linux 8
python-reportlab
Not affected
Red Hat Quay 3
python-reportlab
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | python-reportlab | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python-reportlab | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python-reportlab | Not affected | n/a |
| Red Hat Quay 3 | python-reportlab | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- https://access.redhat.com/security/cve/CVE-2023-33733 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217629 Issue Tracking
- https://github.com/advisories/GHSA-9q9m-c65c-37pq Advisory
- https://github.com/c53elyas/CVE-2023-33733 ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/10/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36WOY22ECJCPOXHVTNCHEWOQLL7JSWP4 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6ALE727IRACYBTTOFIFG57RS4OA2SHIJ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36WOY22ECJCPOXHVTNCHEWOQLL7JSWP4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6ALE727IRACYBTTOFIFG57RS4OA2SHIJ
- https://nvd.nist.gov/vuln/detail/CVE-2023-33733
- https://www.cve.org/CVERecord?id=CVE-2023-33733
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 5, 2023
Updated Jan 8, 2025
Reserved May 22, 2023
Link CVE-2023-33733
CISA Vulnrichment
GHSA-9Q9M-C65C-37PQ Updated Jan 8, 2025