REDHAT-BUG-1264067: Medium severity ipython vulnerability
A vulnerability in IPython allowing maliciously forged file to be opened for editing that could execute javascript code, specifically by being redirected to /files/ due to the mistakenly treating the file as plain text. Versions >= 3.0 and <= 3.2.1 of IPython are affected.
Upstream patch:
https://github.com/ipython/ipython/commit/0a8096adf165e2465550bd5893d7e352544e5967
CVE request:
http://seclists.org/oss-sec/2015/q3/558
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1264067?
The severity of REDHAT-BUG-1264067 is considered to be critical due to the potential execution of malicious JavaScript code.
How do I fix REDHAT-BUG-1264067?
To fix REDHAT-BUG-1264067, upgrade IPython to a version greater than 3.2.1.
Which versions are affected by REDHAT-BUG-1264067?
Versions of IPython from 3.0 up to and including 3.2.1 are affected by REDHAT-BUG-1264067.
What is the nature of the vulnerability in REDHAT-BUG-1264067?
The vulnerability in REDHAT-BUG-1264067 allows for a maliciously forged file to be opened for editing, potentially executing JavaScript code.
Can REDHAT-BUG-1264067 impact user privacy?
Yes, REDHAT-BUG-1264067 can impact user privacy by enabling the execution of unwanted scripts that may compromise sensitive information.