News

Unpatched since 2007 The vulnerability is in the Python tarfile package, in code that uses un-sanitized tarfile.extract () function or the built-in defaults of tarfile.extractall ().
But it's a widely known fact that, if you want code to run in a browser, Python is simply no good – you'll just have to turn to JavaScript," it notes. "Now, however, that may be about to change." ...
Google open-sources Atheris, a tool for finding security bugs in Python code Atheris helps developers find bugs in Python-based codebases using a technique called fuzzing.