CVE-2019-7653
published 2019-02-09CVE-2019-7653: The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code…
PriorityP345critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.26%
81.3th percentile
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | rdflib | < rdflib 4.2.2-2 (bookworm) | rdflib 4.2.2-2 (bookworm) |
| rdflib_project | rdflib | — | — |
| rdflib_project | rdflib | >= 0 < 4.2.2-2 | 4.2.2-2 |
| rdflib_project | rdflib | >= 0 < 4.2.2-2 | 4.2.2-2 |
| rdflib_project | rdflib | >= 0 < 4.2.2-2 | 4.2.2-2 |
| rdflib_project | rdflib | >= 0 < 4.2.2-2 | 4.2.2-2 |
| rdflib_project | rdflib | >= 0 < 4.1.2-3+deb8u1build0.16.04.1 | 4.1.2-3+deb8u1build0.16.04.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34gp-mhv2-cg2f: The Debian python-rdflib-tools 4
ghsa_unreviewed·2022-05-13
CVE-2019-7653 [CRITICAL] CWE-427 GHSA-34gp-mhv2-cg2f: The Debian python-rdflib-tools 4
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
OSV
rdflib vulnerability
osv·2020-09-23·CVSS 9.8
CVE-2019-7653 [CRITICAL] rdflib vulnerability
rdflib vulnerability
Gabriel Corona discovered that RDFLib did not properly load modules on the
command-line. An attacker could possibly use this issue to cause RDFLib to
execute arbitrary code. (CVE-2019-7653)
OSV
CVE-2019-7653: The Debian python-rdflib-tools 4
osv·2019-02-09·CVSS 9.8
CVE-2019-7653 [CRITICAL] CVE-2019-7653: The Debian python-rdflib-tools 4
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
Ubuntu
RDFLib vulnerability
vendor_ubuntu·2020-09-23·CVSS 9.8
CVE-2019-7653 [CRITICAL] RDFLib vulnerability
Title: RDFLib vulnerability
Summary: RDFLib could be made to made to execute arbitrary code if it were running
in a directory with a specially crafted file.
Gabriel Corona discovered that RDFLib did not properly load modules on the
command-line. An attacker could possibly use this issue to cause RDFLib to
execute arbitrary code. (CVE-2019-7653)
Instructions: After a standard system update you need to restart any applications that
make use of RDFLib to make all the necessary changes.
Debian
CVE-2019-7653: rdflib - The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools th...
vendor_debian·2019·CVSS 9.8
CVE-2019-7653 [CRITICAL] CVE-2019-7653: rdflib - The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools th...
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowing code injection, because "python -m" looks in this directory, as demonstrated by rdf2dot. This issue is specific to use of the debian/scripts directory.
Scope: local
bookworm: resolved (fixed in 4.2.2-2)
bullseye: resolved (fixed in 4.2.2-2)
forky: resolved (fixed in 4.2.2-2)
sid: resolved (fixed in 4.2.2-2)
trixie: resolved (fixed in 4.2.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [fedora-all]
bugzilla·2019-02-12·CVSS 9.8
CVE-2019-7653 [CRITICAL] CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [fedora-all]
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory
bugzilla·2019-02-12·CVSS 9.8
CVE-2019-7653 [CRITICAL] CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools
that can load Python modules from the current working directory, allowing code
injection, because "python -m" looks in this directory, as demonstrated by
rdf2dot. This issue is specific to use of the debian/scripts directory.
Reference:
https://bugs.debian.org/921751
Discussion:
Created python-rdflib tracking bugs for this issue:
Affects: fedora-all [bug 1676378]
---
Created python-rdflib tracking bugs for this issue:
Affects: epel-all [bug 1676379]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. R
Bugzilla
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [epel-all]
bugzilla·2019-02-12·CVSS 9.8
CVE-2019-7653 [CRITICAL] CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [epel-all]
CVE-2019-7653 python-rdflib: Improper control of generation of code from current working directory [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
https://bugs.debian.org/921751https://lists.debian.org/debian-lts-announce/2019/03/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00026.htmlhttps://usn.ubuntu.com/4535-1/https://bugs.debian.org/921751https://lists.debian.org/debian-lts-announce/2019/03/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00026.htmlhttps://usn.ubuntu.com/4535-1/
2019-02-09
Published