Package | Installed | Affected | Info |
---|---|---|---|
py | 1.9.0 | <=1.11.0 |
show ** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled. https://github.com/pytest-dev/py/issues/287 |
py | 1.9.0 | <=1.9.0 |
show Py 1.10.0 includes a fix for CVE-2020-29651: A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
Package | Installed | Affected | Info |
---|---|---|---|
py | 1.9.0 | <=1.11.0 |
show ** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled. https://github.com/pytest-dev/py/issues/287 |
py | 1.9.0 | <=1.9.0 |
show Py 1.10.0 includes a fix for CVE-2020-29651: A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
Package | Installed | Affected | Info |
---|---|---|---|
py | 1.9.0 | <=1.11.0 |
show ** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled. https://github.com/pytest-dev/py/issues/287 |
py | 1.9.0 | <=1.9.0 |
show Py 1.10.0 includes a fix for CVE-2020-29651: A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
Package | Installed | Affected | Info |
---|---|---|---|
py | 1.9.0 | <=1.11.0 |
show ** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled. https://github.com/pytest-dev/py/issues/287 |
py | 1.9.0 | <=1.9.0 |
show Py 1.10.0 includes a fix for CVE-2020-29651: A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
Package | Installed | Affected | Info |
---|---|---|---|
py | 1.9.0 | <=1.11.0 |
show ** DISPUTED ** Py throughout 1.11.0 allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data because the InfoSvnCommand argument is mishandled. https://github.com/pytest-dev/py/issues/287 |
py | 1.9.0 | <=1.9.0 |
show Py 1.10.0 includes a fix for CVE-2020-29651: A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
pyyaml | 5.3.1 | <5.4 |
show Pyyaml version 5.4 includes a fix for CVE-2020-14343: A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747. https://bugzilla.redhat.com/show_bug.cgi?id=1860466 |
pyyaml | 5.3.1 | <5.4 |
show Pyyaml version 5.4 includes a fix for CVE-2020-14343: A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747. https://bugzilla.redhat.com/show_bug.cgi?id=1860466 |
https://pyup.io/repos/github/meleca/mr-roboto/python-3-shield.svg
[](https://pyup.io/repos/github/meleca/mr-roboto/)
.. image:: https://pyup.io/repos/github/meleca/mr-roboto/python-3-shield.svg :target: https://pyup.io/repos/github/meleca/mr-roboto/ :alt: Python 3
<a href="https://pyup.io/repos/github/meleca/mr-roboto/"><img src="https://pyup.io/repos/github/meleca/mr-roboto/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/meleca/mr-roboto/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/meleca/mr-roboto/
{<img src="https://pyup.io/repos/github/meleca/mr-roboto/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/meleca/mr-roboto/]
https://pyup.io/repos/github/meleca/mr-roboto/shield.svg
[](https://pyup.io/repos/github/meleca/mr-roboto/)
.. image:: https://pyup.io/repos/github/meleca/mr-roboto/shield.svg :target: https://pyup.io/repos/github/meleca/mr-roboto/ :alt: Updates
<a href="https://pyup.io/repos/github/meleca/mr-roboto/"><img src="https://pyup.io/repos/github/meleca/mr-roboto/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/meleca/mr-roboto/shield.svg(Updates)!:https://pyup.io/repos/github/meleca/mr-roboto/
{<img src="https://pyup.io/repos/github/meleca/mr-roboto/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/meleca/mr-roboto/]