Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu: 3463-1 Moderate: Python Werkzeug Arbitrary Code Execution

ubuntu
Calendar Grey October 25, 2017
Scroller Ubuntu
Debian Security Advisory DSA-4821-1 concerns a vulnerability in python-werkzeug that permits unauthorized command execution through specially crafted inputs.
Werkzeug could be made to run arbitrary code if it opened a specially crafted file.

Summary

Werkzeug could be made to run arbitrary code if it opened a

specially crafted file.

Software Description:

- python-werkzeug: collection of utilities for WSGI applications

Details:

It was discovered that Werkzeug did not properly handle certain

web scripts. A remote attacker could use this to inject arbitrary

code via a field that contains an exception message.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  python-werkzeug                 0.10.4+dfsg1-1ubuntu1.1
  python3-werkzeug                0.10.4+dfsg1-1ubuntu1.1

Ubuntu 14.04 LTS:
  python-werkzeug                 0.9.4+dfsg-1.1ubuntu2.1
  python3-werkzeug                0.9.4+dfsg-1.1ubuntu2.1

In general, a standard system update will make all the necessary
changes.

References

 

  CVE-2016-10516

Severity
important
Lowest
Low
Medium
High
Critical

October 25, 2017

Package Information

  untu1.1
  untu2.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.