Improperly Implemented Security Check for Standard The advisory has been revoked - it doesn't affect any version of package python-sqlalchemy-doc Open this link in a new tab
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RHEL8-PYTHONSQLALCHEMYDOC-1385015
- published 26 Jul 2021
- disclosed 16 Jan 2019
Amendment
The Red Hat
security team deemed this advisory irrelevant for RHEL:8
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python-sqlalchemy-doc
package and not the python-sqlalchemy-doc
package as distributed by RHEL
.
An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources
References
- http://www.securityfocus.com/bid/106670
- https://access.redhat.com/security/cve/CVE-2019-6446
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4/
- https://bugzilla.suse.com/show_bug.cgi?id=1122208
- https://github.com/numpy/numpy/issues/12759
- https://access.redhat.com/errata/RHSA-2019:3335
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00091.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00092.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4/