=========================================================================Ubuntu Security Notice USN-4961-1
May 19, 2021

python-pip vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

pip could be made to install different git revisions.

Software Description:
- python-pip: Python package installer

Details:

It was discovered that pip incorrectly handled unicode separators in git
references. A remote attacker could possibly use this issue to install a
different revision on a repository.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  python3-pip                     20.0.2-5ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4961-1
  https://launchpad.net/bugs/1926957

Package Information:
  https://launchpad.net/ubuntu/+source/python-pip/20.0.2-5ubuntu1.5

Ubuntu 4961-1: pip vulnerability

May 19, 2021
pip could be made to install different git revisions.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-pip 20.0.2-5ubuntu1.5 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4961-1

https://launchpad.net/bugs/1926957

Severity
May 19, 2021

Package Information

https://launchpad.net/ubuntu/+source/python-pip/20.0.2-5ubuntu1.5

Related News