Bug#921751: python-rdflib-tools: Code injection from current working directory

2019-02-08 Thread Salvatore Bonaccorso
Control: retitle -1 python-rdflib-tools: CVE-2019-7653: Code injection from current working directory Hi Gabriel! On Fri, Feb 08, 2019 at 09:49:07PM +0100, Gabriel Corona wrote: > Package: python-rdflib-tools > Version: 4.2.2-1 > Severity: normal > Tags: security > > The CLI tools in python-rdf

Bug#921751: python-rdflib-tools: Code injection from current working directory

2019-02-08 Thread Gabriel Corona
Package: python-rdflib-tools Version: 4.2.2-1 Severity: normal Tags: security The CLI tools in python-rdflib-tools can from load python modules found in the current directory. This happens because "python -m" appends the current directory in the python path. $ echo 'print("Something")' > cgi.