Description
This is a hotfix for the PyArrow security vulnerability CVE-2023-47248.
We generally recommend upgrading to PyArrow 14.0.1 or later, but if you cannot upgrade, this package disables the vulnerability on older versions.
Installation
Use pip to install:
pip install pyarrow_hotfix
Usage
pyarrow_hotfix must be imported in your application or library code for it to take effect:
import pyarrow_hotfix
Supported versions
pyarrow_hotfix supports all Python versions starting from Python 3.5, and all PyArrow versions starting from 0.14.0.
Dependencies
pyarrow_hotfix is a pure Python package that does not have any explicit dependencies, and assumes you have installed pyarrow through other means (such as pip or conda).
Example
>>> import pyarrow as pa
>>> import pyarrow_hotfix
>>>
>>> pa.ipc.open_file('data.arrow')
Traceback (most recent call last):
[ ... ]
RuntimeError: forbidden deserialization of 'arrow.py_extension_type': storage_type = null, serialized = b"\x80\x03cbuiltins\neval\nq\x00X\x15\x00\x00\x00print('hello world!')q\x01\x85q\x02Rq\x03.", pickle disassembly:
0: \x80 PROTO 3
2: c GLOBAL 'builtins eval'
17: q BINPUT 0
19: X BINUNICODE "print('hello world!')"
45: q BINPUT 1
47: \x85 TUPLE1
48: q BINPUT 2
50: R REDUCE
51: q BINPUT 3
53: . STOP
highest protocol among opcodes = 2
License
Like pyarrow, pyarrow_hotfix is distributed under the terms of the Apache License, version 2.0.
Release files for pyarrow-hotfix 0.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pyarrow_hotfix-0.7.tar.gz | 9.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pyarrow_hotfix-0.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.8 kB
Release files / pyarrow_hotfix-0.7.tar.gz
| Download URL | pyarrow_hotfix-0.7.tar.gz |
|---|---|
| Size | 9.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
59399cd58bdd978b2e42816a4183a55c6472d4e33d183351b6069f11ed42661d
|
|
BLAKE2b-256 checksum How to use checksums |
d2edc3e8677f7abf3981838c2af7b5ac03e3589b3ef94fcb31d575426abae904
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.12.3
|
Release files / pyarrow_hotfix-0.7-py3-none-any.whl
| Download URL | pyarrow_hotfix-0.7-py3-none-any.whl |
|---|---|
| Size | 7.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3236f3b5f1260f0e2ac070a55c1a7b339c4bb7267839bd2015e283234e758100
|
|
BLAKE2b-256 checksum How to use checksums |
2ec394ade4906a2f88bc935772f59c934013b4205e773bcb4239db114a6da136
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.12.3
|