Hi Douglas,

It looks to me like this was fixed in Python 3.6, 3.7, 3.8 and 3.9:

From https://python-security.readthedocs.io/vuln/cjk-codec-download-eval.html:


Fixed In

So you should be able to address the CVE by upgrading to one of these patch versions. AFAIK we don't have a timeline for 3.9 support in Python for .NET yet.

cheers,
-Mark

Mark Visser
Senior Dev Manager, M&E
Unity Technologies - www.unity3d.com






On May 12, 2021, at 12:43 PM, Douglas Wyant (Aptly Technology Corporation) via PythonNet <pythonnet@python.org> wrote:

PythonNet,
                Hi folks, I have no idea if this is the correct way to engage support / ask questions, so please redirect me.  We need to deploy Python v3.9 to resolve a known Security issue in older versions.  I’m told we’re blocked on deploying until PythonNet is updated to support v3.9.  So the question is when might that be?
 
CVE-2020-27619: WIndows
Python versions 3.0.0 through 3.9.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected Versions 
Python versions 3.0.0 through 3.9.0 
 
Thanks,
 
Doug Wyant (Aptly Technology Corporation), GSEC, GCIH
Service Engineer 2
Microsoft
_______________________________________________
PythonNet mailing list -- pythonnet@python.org
To unsubscribe send an email to pythonnet-leave@python.org
https://mail.python.org/mailman3/lists/pythonnet.python.org/
Member address: markv@unity3d.com