
概要:python-aiomysql security update
2025/10/31发布
2025/10/31更新
简介
An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2
严重级别
High
主题
An update for python-aiomysql is now available for openEuler-24.03-LTS-SP2. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
描述
**aiomysql** is a "driver" for accessing a `MySQL` database from the asyncio_ (PEP-3156/tulip) framework. It depends on and reuses most parts of PyMySQL_ . *aiomysql* tries to be like awesome aiopg_ library and preserve same api, look and feel. Security Fix(es): aiomysql is a library for accessing a MySQL database from the asyncio. Prior to version 0.3.0, the client-side settings are not checked before sending local files to MySQL server, which allows obtaining arbitrary files from the client using a rogue server. It is possible to create a rogue MySQL server that emulates authorization, ignores client flags and requests arbitrary files from the client by sending a LOAD_LOCAL instruction packet. This issue has been patched in version 0.3.0.(CVE-2025-62611)
影响组件
python-aiomysql
CVE
参考
https://nvd.nist.gov/vuln/detail/CVE-2025-62611
后续改善计划
云顶4008集团官网机会持续跟进该漏洞的最新动态,请关注云顶4008集团官网机官网、官微公告有任何关于此漏洞修复的问题,可以通过以下方式联系我们:
云顶4008集团官网机售后咨询热线:4008-870-872
云顶4008集团官网PSIRT邮箱:psirt@powerleadercom.cn
云顶4008集团官网机官网:https://www.powerleadercom.cn