ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8765-1: python-sql vulnerability

mediumAdvisoryimportance 18
AI summary · glm-5.3

Ubuntu patches python-sql SQL injection flaw where values passed to unary operators are incorrectly escaped.

Ubuntu Security Notice USN-8765-1 fixes a vulnerability in python-sql discovered by Cedric Krier. The library incorrectly escaped values passed to unary operators, allowing an attacker to potentially perform SQL injection attacks against applications using the library.

  • python-sql incorrectly escapes values passed to unary operators
  • Attackers could perform SQL injection via affected applications
  • Discovered by Cedric Krier; fix shipped as USN-8765-1
Full article

Cédric Krier discovered that python-sql incorrectly escaped values passed to unary operators. An attacker could possibly use this issue to perform SQL injection attacks.

This source does not provide full text. Read it at ubuntu.com.