Debian Security Advisory

DLA-1718-1 sqlalchemy -- LTS security update

Date Reported:
18 Mar 2019
Affected Packages:
sqlalchemy
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 922669.
In Mitre's CVE dictionary: CVE-2019-7164, CVE-2019-7548.
More information:

Two vulnerabilities were discovered in SQLALchemy, a Python SQL Toolkit and Object Relational Mapper.

  • CVE-2019-7164

    SQLAlchemy allows SQL Injection via the order_by parameter.

  • CVE-2019-7548

    SQLAlchemy has SQL Injection when the group_by parameter can be controlled.

The SQLAlchemy project warns that these security fixes break the seldom-used text coercion feature.

For Debian 8 Jessie, these problems have been fixed in version 0.9.8+dfsg-0.1+deb8u1.

We recommend that you upgrade your sqlalchemy packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS