=========================================================================Ubuntu Security Notice USN-5812-1
January 19, 2023

python-urllib3 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

urllib3 could be made to stop responding if it received specially crafted
network traffic.

Software Description:
- python-urllib3: HTTP library with thread-safe connection pooling

Details:

It was discovered that urllib3 incorrectly handled certain characters
in URLs. A remote attacker could possibly use this issue to cause urllib3
to consume resources, leading to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
   python3-urllib3                 1.25.8-2ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5812-1
   CVE-2021-33503

Package Information:
   https://launchpad.net/ubuntu/+source/python-urllib3/1.25.8-2ubuntu0.2

Ubuntu 5812-1: urllib3 vulnerability

January 19, 2023
urllib3 could be made to stop responding if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-urllib3 1.25.8-2ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5812-1

CVE-2021-33503

Severity
January 19, 2023

Package Information

https://launchpad.net/ubuntu/+source/python-urllib3/1.25.8-2ubuntu0.2

Related News