—
PYSEC-2019-102
Quick fix
PYSEC-2019-102 — limnoria: upgrade to the fixed version with the command below.
pip install --upgrade 'limnoria>=3848ae78de45b35c029cc333963d436b9d2f0a35'Details
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/limnoria
Introduced in:
0Fixed in: 3848ae78de45b35c029cc333963d436b9d2f0a35Fix
pip install --upgrade 'limnoria>=3848ae78de45b35c029cc333963d436b9d2f0a35'References
- https://github.com/ProgVal/Limnoria/commit/3848ae78de45b35c029cc333963d436b9d2f0a35[FIX]
- https://github.com/ProgVal/Limnoria/wiki/math-eval-vulnerability[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/54CQM2TEXRADLE77VOMCPHL5PBHR3ZWJ/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5P2AGND54UIJV3WHOYO2YINIXSDGAAPO/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DRNOUHFEN75QAIKT4Y3HDN3TT5LSIWN2/[WEB]
- https://github.com/advisories/GHSA-6g88-vr3v-76mf[ADVISORY]