VDB
Sign up
—

PYSEC-2016-36

Quick fix

PYSEC-2016-36 — radicale: upgrade to the fixed version with the command below.

pip install --upgrade 'radicale>=bcaf452e516c02c9bed584a73736431c5e8831f1'

Details

The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/radicale
Introduced in: 0Fixed in: bcaf452e516c02c9bed584a73736431c5e8831f1
Fixpip install --upgrade 'radicale>=bcaf452e516c02c9bed584a73736431c5e8831f1'

References