云顶集团-www.4008.com|中国·官网首发


openEuler-SA-2025-2616安全公告

概要:python-aiomysql security update

2025/10/31发布

2025/10/31更新


简介

An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2


严重级别

High


主题

An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.


描述

**aiomysql** is a "driver" for accessing a `MySQL` database from the asyncio_ (PEP-3156/tulip) framework. It depends on and reuses most parts of PyMySQL_ . *aiomysql* tries to be like awesome aiopg_ library and preserve same api, look and feel. Security Fix(es): aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. This issue has been patched in version 0.3.0.(CVE-2025-62611)


影响组件

python-aiomysql


CVE

CVE-2025-62611


参考

https://nvd.nist.gov/vuln/detail/CVE-2025-62611


后续改善计划

云顶4008集团官网机会持续跟进该漏洞的最新动态,请关注云顶4008集团官网机官网、官微公告有任何关于此漏洞修复的问题,可以通过以下方式联系我们:

云顶4008集团官网机售后咨询热线:4008-870-872

云顶4008集团官网PSIRT邮箱:psirt@powerleadercom.cn

云顶4008集团官网机官网:https://www.powerleadercom.cn


XML 地图