日韩欧洲电影免费看,日韩高清视频在线观看,香蕉视频安卓下载污,欧美日韩视频二区,国产精品成久久久久三级蜜桃,香港三级精品三级在线,巨乳乱伦熟女,一本二本三本高清不卡区

?
openEuler-SA-2025-2616安全公告

概要:python-aiomysql security update

2025/10/31發(fā)布

2025/10/31更新


簡介

An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2


嚴(yán)重級別

High


主題

An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.


描述

**aiomysql** is a "driver" for accessing a `MySQL` database from the asyncio_ (PEP-3156/tulip) framework. It depends on and reuses most parts of PyMySQL_ . *aiomysql* tries to be like awesome aiopg_ library and preserve same api, look and feel. Security Fix(es): aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. This issue has been patched in version 0.3.0.(CVE-2025-62611)


影響組件

python-aiomysql


CVE

CVE-2025-62611


參考

https://nvd.nist.gov/vuln/detail/CVE-2025-62611


后續(xù)改善計(jì)劃

寶德計(jì)算機(jī)會(huì)持續(xù)跟進(jìn)該漏洞的最新動(dòng)態(tài),請關(guān)注寶德計(jì)算機(jī)官網(wǎng)、官微公告有任何關(guān)于此漏洞修復(fù)的問題,可以通過以下方式聯(lián)系我們:

寶德計(jì)算機(jī)售后咨詢熱線:4008-870-872

寶德PSIRT郵箱:psirt@powerleadercom.cn

寶德計(jì)算機(jī)官網(wǎng):https://www.powerleadercom.cn

?