From 7ecad21414c9d98e27737a3381e60b11b97cc407 Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 28 Jan 2020 21:06:22 +0100 Subject: Add fixed version for CVE-2019-17626/python-reportlab --- data/CVE/list | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'data') diff --git a/data/CVE/list b/data/CVE/list index a035aca89e..5a081a3a14 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -23318,7 +23318,7 @@ CVE-2019-17628 CVE-2019-17627 (The Yale Bluetooth Key application for mobile devices allows unauthori ...) NOT-FOR-US: Yale Bluetooth Key application for mobile devices CVE-2019-17626 (ReportLab through 3.5.26 allows remote code execution because of toCol ...) - - python-reportlab (bug #942763) + - python-reportlab 3.5.34-1 (bug #942763) NOTE: https://bitbucket.org/rptlab/reportlab/issues/199/eval-in-colorspy-leads-to-remote-code NOTE: https://hg.reportlab.com/hg-public/reportlab/rev/51a521ad7dd3 CVE-2019-17625 (There is a stored XSS in Rambox 0.6.9 that can lead to code execution. ...) -- cgit v1.2.3