CVE-2019-19450
Summary
| CVE | CVE-2019-19450 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 14:15:00 UTC |
| Updated | 2024-02-01 01:08:00 UTC |
| Description | paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160969 Oracle Enterprise Linux Security Update for python-reportlab (ELSA-2023-5616)
- 161000 Oracle Enterprise Linux Security Update for python-reportlab (ELSA-2023-5790)
- 242146 Red Hat Update for python-reportlab (RHSA-2023:5616)
- 242185 Red Hat Update for python-reportlab (RHSA-2023:5790)
- 242186 Red Hat Update for python-reportlab (RHSA-2023:5786)
- 242187 Red Hat Update for python-reportlab (RHSA-2023:5789)
- 242191 Red Hat Update for python-reportlab (RHSA-2023:5787)
- 242364 Red Hat Update for python-reportlab (RHSA-2023:5788)
- 257307 CentOS Security Update for python-reportlab Security Update (CESA-2023:5616)
- 356397 Amazon Linux Security Advisory for python-reportlab : ALAS2-2023-2285
- 378962 Alibaba Cloud Linux Security Update for python-reportlab (ALINUX3-SA-2023:0130)
- 379035 Alibaba Cloud Linux Security Update for python-reportlab (ALINUX2-SA-2023:0042)
- 6000091 Debian Security Update for python-reportlab (DLA 3590-1)
- 755036 SUSE Enterprise Linux Security Update for python-reportlab (SUSE-SU-2023:3972-1)
- 941307 AlmaLinux Security Update for python-reportlab (ALSA-2023:5790)
- 995359 Python (Pip) Security Update for reportlab (GHSA-pj98-2xf6-cff5)