ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with '<span color="' followed by arbitrary Python code.
{
"binaries": [
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python-renderpm"
},
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python-reportlab"
},
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python-reportlab-accel"
},
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python3-renderpm"
},
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python3-reportlab"
},
{
"binary_version": "3.3.0-1ubuntu0.1",
"binary_name": "python3-reportlab-accel"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python-renderpm"
},
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python-reportlab"
},
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python-reportlab-accel"
},
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python3-renderpm"
},
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python3-reportlab"
},
{
"binary_version": "3.4.0-3ubuntu0.1",
"binary_name": "python3-reportlab-accel"
}
],
"availability": "No subscription required"
}