bpo-41944: No longer call eval() on content received via HTTP in the UnicodeNames tests (GH-22575)
Similarly to GH-22566, those tests called eval() on content received via HTTP in test_named_sequences_full. This likely isn't exploitable because unicodedata.lookup(seqname) is called before self.checkletter(seqname, None) - thus any string which isn't a valid unicode character name wouldn't ever reach the checkletter method. Still, it's probably better to be safe than sorry.
F
Florian Bruhin committed
a8bf44d04915f7366d9f8dfbf84822ac37a4bab3
Parent: 2ef5caa
Committed by GitHub <noreply@github.com>
on 10/6/2020, 2:21:56 PM