QID 995990
Date Published: 2023-11-20
QID 995990: Python (Pip) Security Update for ibis-framework (GHSA-x563-6hqv-26mr)
Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x563-6hqv-26mr for updates and patch information.
Vendor References
- GHSA-x563-6hqv-26mr -
github.com/advisories/GHSA-x563-6hqv-26mr
CVEs related to QID 995990
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x563-6hqv-26mr | ibis-framework |
|