<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4641 — Moderate: python38:3.8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4641</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python38-Cython, AlmaLinux:8: python38-asn1crypto, AlmaLinux:8: python38-cffi, AlmaLinux:8: python38-chardet, AlmaLinux:8: python38-cryptography, AlmaLinux:8: python38-idna, AlmaLinux:8: python38-markupsafe, AlmaLinux:8: python38-mod_wsgi, AlmaLinux:8: python38-psycopg2, AlmaLinux:8: python38-psycopg2-doc and 6 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: python38 (3.8.3). (BZ#1847416)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PyYAML: command execution through python/object/apply constructor in FullLoader (CVE-2019-20477)&lt;/p&gt;
&lt;p&gt;* python: infinite loop in the tarfile module via crafted TAR archive (CVE-2019-20907)&lt;/p&gt;
&lt;p&gt;* PyYAML: arbitrary command execution through python/object/new when FullLoader is used (CVE-2020-1747)&lt;/p&gt;
&lt;p&gt;* python: wrong backtracking in urllib.request.AbstractBasicAuthHandler allows for a ReDoS (CVE-2020-8492)&lt;/p&gt;
&lt;p&gt;* python: DoS via inefficiency in IPv{4,6}Interface classes (CVE-2020-14422)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python38-Cython, AlmaLinux:8: python38-asn1crypto, AlmaLinux:8: python38-cffi, AlmaLinux:8: python38-chardet, AlmaLinux:8: python38-cryptography, AlmaLinux:8: python38-idna, AlmaLinux:8: python38-markupsafe, AlmaLinux:8: python38-mod_wsgi, AlmaLinux:8: python38-psycopg2, AlmaLinux:8: python38-psycopg2-doc and 6 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: python38 (3.8.3). (BZ#1847416)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PyYAML: command execution through python/object/apply constructor in FullLoader (CVE-2019-20477)&lt;/p&gt;
&lt;p&gt;* python: infinite loop in the tarfile module via crafted TAR archive (CVE-2019-20907)&lt;/p&gt;
&lt;p&gt;* PyYAML: arbitrary command execution through python/object/new when FullLoader is used (CVE-2020-1747)&lt;/p&gt;
&lt;p&gt;* python: wrong backtracking in urllib.request.AbstractBasicAuthHandler allows for a ReDoS (CVE-2020-8492)&lt;/p&gt;
&lt;p&gt;* python: DoS via inefficiency in IPv{4,6}Interface classes (CVE-2020-14422)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4641</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-20477 — CVE-2019-20477 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-20477</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-20477</guid>
    </item>
    <item>
      <title>BREW-ansible-cmdb-CVE-2019-20477 — Deserialization of Untrusted Data in PyYAML</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2019-20477</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2019-20477</guid>
    </item>
    <item>
      <title>certfr-2022-avi-278 — De multiples vulnérabilités ont été découvertes dans IBM Spectrum
discover. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</link>
      <description>certfr-2022-avi-278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-278</guid>
    </item>
    <item>
      <title>EUVD-2026-59954</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-59954</link>
      <description>EUVD-2026-59954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-59954</guid>
    </item>
    <item>
      <title>fkie_cve-2019-20477</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-20477</link>
      <description>&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-20477</guid>
    </item>
    <item>
      <title>GHSA-3pqx-4fqf-j49f — Deserialization of Untrusted Data in PyYAML</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3pqx-4fqf-j49f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3pqx-4fqf-j49f</guid>
    </item>
    <item>
      <title>gsd-2019-20477</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-20477</link>
      <description>gsd-2019-20477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-20477</guid>
    </item>
    <item>
      <title>PYSEC-2020-176</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-176</guid>
    </item>
    <item>
      <title>RHSA-2020:4641 — Red Hat Security Advisory: python38:3.8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4641</link>
      <description>&lt;p&gt;PyYAML: command execution through python/object/apply constructor in FullLoader python: infinite loop in the tarfile module via crafted TAR archive PyYAML: arbitrary command execution through python/object/new when FullLoader is used python: wrong backtracking in urllib.request.AbstractBasicAuthHandler allows for a ReDoS python: DoS via inefficiency in IPv{4,6}Interface classes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PyYAML: command execution through python/object/apply constructor in FullLoader python: infinite loop in the tarfile module via crafted TAR archive PyYAML: arbitrary command execution through python/object/new when FullLoader is used python: wrong backtracking in urllib.request.AbstractBasicAuthHandler allows for a ReDoS python: DoS via inefficiency in IPv{4,6}Interface classes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4641</guid>
    </item>
    <item>
      <title>RHSA-2021:0420 — Red Hat Security Advisory: Red Hat Quay v3.4.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0420</link>
      <description>&lt;p&gt;openstack-mistral: information disclosure in mistral log waitress: HTTP request smuggling through LF vs CRLF handling waitress: HTTP request smuggling through invalid Transfer-Encoding waitress: HTTP Request Smuggling through Invalid whitespace characters in headers python-pillow: uncontrolled resource consumption in FpxImagePlugin.py PyYAML: command execution through python/object/apply constructor in FullLoader python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images yarn: Arbitrary filesystem write via tar expansion python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files python-pillow: two buffer overflows in libImaging/TiffDecode.c due to small buffers allocated in ImagingLibTiffDecode() python-pillow: multiple out-of-bounds reads via a crafted JP2 file python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openstack-mistral: information disclosure in mistral log waitress: HTTP request smuggling through LF vs CRLF handling waitress: HTTP request smuggling through invalid Transfer-Encoding waitress: HTTP Request Smuggling through Invalid whitespace characters in headers python-pillow: uncontrolled resource consumption in FpxImagePlugin.py PyYAML: command execution through python/object/apply constructor in FullLoader python-pillow: Integer overflow leading to buffer overflow in ImagingLibTiffDecode python-pillow: out-of-bounds write in expandrow in libImaging/SgiRleDecode.c python-pillow: improperly restricted operations on memory buffer in libImaging/PcxDecode.c python-pillow: out-of-bounds read in ImagingFliDecode when loading FLI images yarn: Arbitrary filesystem write via tar expansion python-pillow: multiple out-of-bounds reads in libImaging/FliDecode.c python-pillow: an out-of-bounds read in libImaging/PcxDecode.c can occur when reading PCX files python-pillow: two buffer overflows in libImaging/TiffDecode.c due to small buffers allocated in ImagingLibTiffDecode() python-pillow: multiple out-of-bounds reads via a crafted JP2 file python-pillow: out-of-bounds reads/writes in the parsing of SGI image files in expandrow/expandrow2 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0420</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2019-20477</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-20477</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: pyyaml&lt;/p&gt;
&lt;p&gt;PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-20477</guid>
    </item>
  </channel>
</rss>
