This issue tracker has been migrated to GitHub, and is currently read-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.

Author vstinner
Recipients barry, christian.heimes, kristjan.jonsson, pitrou, serhiy.storchaka, vstinner
Date 2013-10-11.11:58:48
SpamBayes Score -1.0
Marked as misclassified Yes
Message-id <1381492728.83.0.326907657479.issue19219@psf.upfronthosting.co.za>
In-reply-to
Content
"You should ensure that loaded bytes are ASCII-only. Otherwise broken or malicious marshalled data will compromise you program."

This is not new, see the red warning in marshal doc:

"""
Warning

The marshal module is not intended to be secure against erroneous or maliciously constructed data. Never unmarshal data received from an untrusted or unauthenticated source.
"""
History
Date User Action Args
2013-10-11 11:58:48vstinnersetrecipients: + vstinner, barry, pitrou, kristjan.jonsson, christian.heimes, serhiy.storchaka
2013-10-11 11:58:48vstinnersetmessageid: <1381492728.83.0.326907657479.issue19219@psf.upfronthosting.co.za>
2013-10-11 11:58:48vstinnerlinkissue19219 messages
2013-10-11 11:58:48vstinnercreate