QID 980845
QID 980845: Python (pip) Security Update for python-gnupg (GHSA-vcr5-xr9h-mvc5)
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vcr5-xr9h-mvc5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vcr5-xr9h-mvc5 -
github.com/advisories/GHSA-vcr5-xr9h-mvc5
CVEs related to QID 980845
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vcr5-xr9h-mvc5 | python-gnupg |
|