VDB
Sign up
—

PYSEC-2020-233

Quick fix

PYSEC-2020-233 — freewvs: upgrade to the fixed version with the command below.

pip install --upgrade 'freewvs>=83a6b55c0435c69f447488b791555e6078803143'

Details

In freewvs before 0.1.1, a directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator scans the dirs of potentially untrusted users. This has been patched in 0.1.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/freewvs
Introduced in: 0Fixed in: 83a6b55c0435c69f447488b791555e6078803143
Fixpip install --upgrade 'freewvs>=83a6b55c0435c69f447488b791555e6078803143'

References