Uploaded image for project: 'Apache Arrow'
  1. Apache Arrow
  2. ARROW-18302

[Python] Is pyarrow vulnerable to CVE-2022-3786?

    XMLWordPrintableJSON

Details

    Description

      Since pyarrow seems to have no disposition on this bug already, I am curious if the implementation of openssl included with pyarrow is vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2022-3786

      Here is the commit of openssl that this is fixed in:

      https://github.com/openssl/openssl/commit/c42165b5706e42f67ef8ef4c351a9a4c5d21639a

      Attachments

        Issue Links

          Activity

            People

              raulcd Raúl Cumplido
              chaig Christina
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2h 10m
                  2h 10m