VDB
Sign up
—

PYSEC-2020-92

Quick fix

PYSEC-2020-92 — py: upgrade to the fixed version with the command below.

pip install --upgrade 'py>=1.10.0'

Details

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/py
Introduced in: 0Fixed in: 1.10.0
Fixpip install --upgrade 'py>=1.10.0'

References