| Name | CVE-2019-19275 |
| Description | typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. ... |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
The information below is based on the following data on fixed versions.
Notes
[buster] - python3-typed-ast <no-dsa> (Minor issue)
[stretch] - python3-typed-ast <not-affected> (Vulnerable code introduced later)
https://bugs.python.org/issue36495
Introduced by: https://github.com/python/typed_ast/commit/156afcb26c198e162504a57caddfe0acd9ed7dce (1.3.0)
Fixed by: https://github.com/python/typed_ast/commit/dc317ac9cff859aa84eeabe03fb5004982545b3b (1.3.2)