id: PYSEC-2019-155 details: python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file. affected: - package: name: python-dbusmock ecosystem: PyPI purl: pkg:pypi/python-dbusmock ranges: - type: GIT repo: https://github.com/martinpitt/python-dbusmock events: - introduced: '0' - fixed: 4e7d0df9093 - type: ECOSYSTEM events: - introduced: '0' - fixed: 0.15.1 versions: - 0.0.2 - 0.0.3 - '0.1' - 0.1.1 - 0.1.2 - 0.1.3 - '0.10' - 0.10.1 - 0.10.2 - 0.10.3 - '0.11' - 0.11.1 - 0.11.2 - 0.11.3 - 0.11.4 - '0.12' - '0.13' - '0.14' - '0.15' - 0.2.0 - 0.2.1 - 0.2.2 - '0.3' - 0.3.1 - 0.4.0 - '0.5' - '0.6' - 0.6.1 - 0.6.2 - 0.6.3 - '0.7' - 0.7.1 - 0.7.2 - '0.8' - 0.8.1 - '0.9' - 0.9.1 - 0.9.2 references: - type: FIX url: https://github.com/martinpitt/python-dbusmock/commit/4e7d0df9093 - type: ADVISORY url: https://github.com/advisories/GHSA-74xw-82v7-hmrm aliases: - CVE-2015-1326 - GHSA-74xw-82v7-hmrm modified: '2021-07-05T00:01:25.330872Z' published: '2019-04-22T16:29:00Z'