ReportLab 3.6.13 - security fix

Andy Robinson <[email protected]> Thu, 27 Apr 2023 14:31:57 +0100
Newsgroups gmane.comp.python.reportlab.user
Message-ID <CABjtApuLcGAupOBC=bj5Pn+via1hWUUK=ZVmJKik1STsL7ZKWQ@mail.gmail.com>
--===============6827553474166968791==
Content-Type: multipart/alternative; boundary="000000000000161c3905fa516256"

--000000000000161c3905fa516256
Content-Type: text/plain; charset="UTF-8"

Version 3.6.13 of reportlab, and its commercial counterpart, rlextra - have
been released.

These fix a potential security vulnerability in the parsing of colours.
Previously, Iif someone had coded an application allowing user-input
expressions to be passed to our toColor constructor function, there was a
way to execute inappropriate code.  If you are doing this, please upgrade
to the newest version.

If, however, there are no external inputs and colours are set by you in
code (or validated to be simple and reasonable expressions), there is no
vulnerability.

Thanks for Elyas Damej of https://cure53.de/ for devising an ingenious
exploit, and reporting it to us first!

Best Regards

-- 
Andy Robinson
Managing Director, ReportLab

--000000000000161c3905fa516256
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><div><br></div>Version 3.6.13 of reportla=
b, and its commercial counterpart, rlextra - have been released.=C2=A0=C2=
=A0</div><div dir=3D"ltr"><br></div><div dir=3D"ltr">These fix a potential =
security vulnerability in the parsing of colours. Previously, Iif someone h=
ad coded an application allowing user-input expressions to be passed to our=
 toColor constructor function, there was a way to execute inappropriate cod=
e.=C2=A0 If you are doing this, please upgrade to the newest version.</div>=
<div dir=3D"ltr"><br></div><div>If, however, there are no external inputs a=
nd colours are set by you in code (or validated to be simple and reasonable=
 expressions), there is no vulnerability.</div><div dir=3D"ltr"><br></div><=
div dir=3D"ltr">Thanks for Elyas Damej of <a href=3D"https://cure53.de/">ht=
tps://cure53.de/</a> for devising an ingenious exploit, and reporting it to=
 us first!<br clear=3D"all"><div><br></div><div>Best Regards</div><div><br>=
</div><span class=3D"gmail_signature_prefix">-- </span><br><div dir=3D"ltr"=
 class=3D"gmail_signature"><div dir=3D"ltr">Andy Robinson<br>Managing Direc=
tor, ReportLab<br><br></div></div></div></div>

--000000000000161c3905fa516256--

--===============6827553474166968791==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline