Improper Input Validation in python-dbusmock
High severity
GitHub Reviewed
Published
Apr 23, 2019
to the GitHub Advisory Database
•
Updated Oct 15, 2024
Description
Published by the National Vulnerability Database
Apr 22, 2019
Reviewed
Apr 23, 2019
Published to the GitHub Advisory Database
Apr 23, 2019
Last updated
Oct 15, 2024
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
References