PT-2020-16726 · Python+9 · Python+9

Published

2020-10-05

·

Updated

2025-10-05

·

CVE-2020-27619

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Python versions 3 through 3.9.0
Description The issue arises from the Lib/test/multibytecodec support.py CJK codec tests in Python, which call eval() on content retrieved via HTTP. This poses a risk due to the potential for executing arbitrary code.
Recommendations For Python versions 3 through 3.9.0, consider disabling the eval() function calls in the Lib/test/multibytecodec support.py CJK codec tests until a patch is available. Restrict access to the vulnerable CJK codec tests to minimize the risk of exploitation. Avoid using the eval() function on content retrieved via HTTP in the affected tests.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2021:4151
ALSA-2021:4162
ALT-PU-2021-1384
ALT-PU-2021-2420
ALT-PU-2021-2478
ALT-PU-2021-2653
ALT-PU-2024-3474
BIT-LIBPYTHON-2020-27619
BIT-PYTHON-2020-27619
BIT-PYTHON-MIN-2020-27619
CESA-2021_1633
CESA-2021_4151
CESA-2021_4162
CVE-2020-27619
MGASA-2020-0477
MGASA-2021-0327
OPENSUSE-SU-2020:2332-1
OPENSUSE-SU-2020:2333-1
OPENSUSE-SU-2020_2332-1
OPENSUSE-SU-2020_2333-1
OPENSUSE-SU-2024:11284-1
PSF-2020-6
RHSA-2021:1633
RHSA-2021:3252
RHSA-2021:3254
RHSA-2021:4151
RHSA-2021:4162
RHSA-2021_1633
RHSA-2021_4151
RHSA-2021_4162
RLSA-2021:4151
RLSA-2021:4162
SUSE-SU-2020:3865-1
SUSE-SU-2020:3930-1
SUSE-SU-2021:1621-1
USN-4754-1
USN-4754-2
USN-4754-3
USN-6891-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Python
Red Hat
Rocky Linux
Suse
Ubuntu