rpm package
suse/python-typed-ast&distro=SUSE Package Hub 15 SP1
pkg:rpm/suse/python-typed-ast&distro=SUSE%20Package%20Hub%2015%20SP1
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-19275 | Hig | 7.5 | < 1.3.1-bp151.2.6.1 | 1.3.1-bp151.2.6.1 | Nov 26, 2019 | typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-b | |
| CVE-2019-19274 | Hig | 7.5 | < 1.3.1-bp151.2.6.1 | 1.3.1-bp151.2.6.1 | Nov 26, 2019 | typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a |
- affected < 1.3.1-bp151.2.6.1fixed 1.3.1-bp151.2.6.1
typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-b
- affected < 1.3.1-bp151.2.6.1fixed 1.3.1-bp151.2.6.1
typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a