0.14.1
4 years ago
28 days ago
Known vulnerabilities in the pyp2spec package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
pyp2spec is a Generate a valid Fedora specfile from Python package from PyPI Affected versions of this package are vulnerable to Arbitrary Code Injection in the process of writing package metadata into the generated spec file without escaping RPM macro directives. An attacker can execute arbitrary commands on the build machine by publishing a malicious package with crafted metadata fields that are evaluated during spec parsing. How to fix Arbitrary Code Injection? Upgrade | [,0.14.1) |