Path to this page:
Subject: CVS commit: pkgsrc/databases/py-pymysql
From: Adam Ciarcinski
Date: 2024-05-22 09:18:56
Message id: 20240522071856.96638FA2C@cvs.NetBSD.org
Log Message:
py-pymysql: updated to 1.1.1
v1.1.1
> [!WARNING]
> This release fixes a vulnerability (CVE-2024-36039).
> All users are recommended to update to this version.
>
> If you can not update soon, check the input value from
> untrusted source has an expected type. Only dict input
> from untrusted source can be an attack vector.
* Prohibit dict parameter for `Cursor.execute()`. It didn't produce valid SQL
and might cause SQL injection. (CVE-2024-36039)
Files: