Skip to content

Security bug in tkinter allows for untrusted, arbitrary code execution. #60452

@RamchandraApte

Description

@RamchandraApte
BPO 16248
Nosy @warsaw, @birkenfeld, @terryjreedy, @mdickinson, @pitrou, @larryhastings, @tiran, @benjaminp, @asvetlov, @skrah, @zware
Files
  • exploit.py
  • issue16248-2.x.patch: 2.x patch
  • issue16248-3.x.patch: 3.x patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = <Date 2013-09-15.19:59:57.526>
    created_at = <Date 2012-10-16.15:29:21.664>
    labels = ['type-security', 'expert-tkinter', 'release-blocker']
    title = 'Security bug in tkinter allows for untrusted, arbitrary code execution.'
    updated_at = <Date 2013-09-15.19:59:57.525>
    user = 'https://bugs.python.org/RamchandraApte'

    bugs.python.org fields:

    activity = <Date 2013-09-15.19:59:57.525>
    actor = 'pitrou'
    assignee = 'none'
    closed = True
    closed_date = <Date 2013-09-15.19:59:57.526>
    closer = 'pitrou'
    components = ['Tkinter']
    creation = <Date 2012-10-16.15:29:21.664>
    creator = 'Ramchandra Apte'
    dependencies = []
    files = ['27823', '27937', '27938']
    hgrepos = []
    issue_num = 16248
    keywords = ['patch']
    message_count = 64.0
    messages = ['173047', '173048', '173050', '173051', '173125', '173191', '173230', '173231', '173278', '174299', '174300', '174317', '174319', '174396', '174420', '174429', '174450', '174460', '174462', '174463', '174464', '174466', '174469', '174471', '174476', '174479', '174488', '174509', '174553', '174556', '174813', '175253', '177218', '177219', '177220', '177222', '182507', '182511', '182524', '182525', '182526', '182527', '182532', '182565', '182566', '182568', '182569', '194091', '194094', '194096', '194112', '194114', '194639', '195091', '195093', '195599', '195600', '195737', '195738', '197689', '197690', '197697', '197825', '197826']
    nosy_count = 15.0
    nosy_names = ['barry', 'georg.brandl', 'terry.reedy', 'mark.dickinson', 'pitrou', 'larry', 'christian.heimes', 'benjamin.peterson', 'gpolo', 'Arfrever', 'asvetlov', 'skrah', 'python-dev', 'Ramchandra Apte', 'zach.ware']
    pr_nums = []
    priority = 'release blocker'
    resolution = 'fixed'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue16248'
    versions = ['Python 3.1']

    Metadata

    Metadata

    Assignees

    No one assigned
      No fields configured for issues without a type.

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions