A vulnerability allowing arbitrary code execution was found in ReportLab.
|Package||dev-python/reportlab on all architectures|
|Affected versions||< 3.5.42|
|Unaffected versions||>= 3.5.42|
ReportLab is an Open Source Python library for generating PDFs and graphics.
ReportLab was found to be mishandling XML documents and may evaluate the contents without checking for their safety.
A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition.
There is no known workaround at this time.
All ReportLab users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-python/reportlab-3.5.42"
July 27, 2020
July 27, 2020: 1