Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian DSA-5065-1 Addressed Cross-User Vulnerability in IPython

debian
Calendar Grey January 31, 2022
Debian Logo
A recent security update for IPython on Debian systems addresses critical cross-user vulnerabilities that could lead to unauthorized access and data theft
It was discovered that IPython, an enhanced interactive Python shell, executed config files from the current working directory, which could result in cross-user attacks if run from...

Summary

It was discovered that IPython, an enhanced interactive Python shell,
executed config files from the current working directory, which could
result in cross-user attacks if run from a directory multiple usersmay write to.

For the oldstable distribution (buster), this problem has been fixed
in version 5.8.0-1+deb10u1.

For the stable distribution (bullseye), this problem has been fixed in
version 7.20.0-1+deb11u1.

We recommend that you upgrade your ipython packages.

For the detailed security status of ipython please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ipython

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: ipython
CVE ID: CVE-2022-21699

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here