NA

CVE-2024-34062

Published: 03/05/2024 Updated: 03/05/2024

Vulnerability Summary

tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, allowing arbitrary code execution. This issue is only locally exploitable and had been addressed in release version 4.66.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Vendor Advisories

Debian Bug report logs - #1070372 tqdm: CVE-2024-34062 Package: src:tqdm; Maintainer for src:tqdm is Daniel Baumann <danielbaumann@progress-linuxorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 4 May 2024 15:57:06 UTC Severity: important Tags: security, upstream Found in version tqdm/4662-3 Fix ...