—
PYSEC-2014-84
Quick fix
PYSEC-2014-84 — logilab-common: upgrade to the fixed version with the command below.
pip install --upgrade 'logilab-common>=0.60.1'Details
The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/logilab-common
Introduced in:
0Fixed in: 0.60.1Fix
pip install --upgrade 'logilab-common>=0.60.1'References
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html[WEB]
- http://www.logilab.org/ticket/207562[WEB]
- http://secunia.com/advisories/57209[ADVISORY]
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051[WEB]
- http://comments.gmane.org/gmane.comp.security.oss.general/11986[WEB]
- https://github.com/advisories/GHSA-g5m2-22h2-rr3j[ADVISORY]