Ubuntu Security Notice USN-4655-1
December 01, 2020

python-werkzeug vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS


Several security issues were fixed in Werkzeug.

Software Description:
- python-werkzeug: collection of utilities for WSGI applications (Python 2.x)


It was discovered that Werkzeug has insufficient debugger PIN randomness.
An attacker could use this issue to access sensitive information. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-14806)

It was discovered that Werkzeug incorrectly handled certain URLs.
An attacker could possibly use this issue to cause pishing attacks.
This issue only affected Ubuntu 16.04 LTS. (CVE-2020-28724)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  python-werkzeug                 0.14.1+dfsg1-1ubuntu0.1
  python3-werkzeug                0.14.1+dfsg1-1ubuntu0.1

Ubuntu 16.04 LTS:
  python-werkzeug                 0.10.4+dfsg1-1ubuntu1.2
  python3-werkzeug                0.10.4+dfsg1-1ubuntu1.2

In general, a standard system update will make all the necessary changes.

  CVE-2019-14806, CVE-2020-28724

Package Information: