UBUNTU-CVE-2022-48565
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-48565
UBUNTU-CVE-2022-48565
Summary:
Details: An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
References: https://ubuntu.com/security/CVE-2022-48565, https://github.com/python/cpython/commit/05ee790f4d1cd8725a90b54268fc1dfe5b4d1fa2, https://github.com/python/cpython/commit/479553c7c11306a09ce34edb6ef208133b7b95fe, https://github.com/python/cpython/commit/e512bc799e3864fe3b1351757261762d63471efc, https://ubuntu.com/security/notices/USN-6354-1, https://www.cve.org/CVERecord?id=CVE-2022-48565, https://ubuntu.com/security/notices/USN-6891-1, https://ubuntu.com/security/notices/USN-7180-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/python2.7?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
