Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7 MGASA-2021-0054 Critical: Python-Pip Directory Traversal Attack

mageia
Calendar Grey January 25, 2021
Dist Mageia Esm H88
Important python-pip security patch addresses directory traversal vulnerability impacting Mageia 7. Discover the details regarding the risks involved.
It was discovered that pip did not properly sanitize the filename during pip install

Summary

It was discovered that pip did not properly sanitize the filename during pip install. A remote attacker could possible use this issue to read and write arbitrary files on the host filesystem as root, resulting in a directory traversal attack (CVE-2019-20916).
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). The python-pip package bundles a copy of python-urllib3, which was affected by this issue. The bundled copy was patched to fix the issue (CVE-2020-26137).

References

- https://bugs.mageia.org/show_bug.cgi?id=27301

- https://bugs.mageia.org/show_bug.cgi?id=27407

- https://ubuntu.com/security/notices/USN-4601-1

- https://ubuntu.com/security/notices/USN-4570-1

- https://www.cve.org/CVERecord?id=CVE-2019-20916

- https://www.cve.org/CVERecord?id=CVE-2020-26137

Resolution

SRPMS

- 7/core/python-pip-19.0.3-1.3.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0054.html
Type: security
CVE: CVE-2019-20916, CVE-2020-26137

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here