Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 22.10 USN-5821-3 Moderate: Python-Pip Denial Of Service

ubuntu
Calendar Grey February 28, 2023
Scroller Ubuntu
USN-5830-4 resolves a vulnerability in python-setuptools impacting several Ubuntu versions through an urgent patch.
USN-5821-1 caused a regression in pip.

Summary

USN-5821-1 caused a regression in pip.

Software Description:

- python-pip: Python package installer

Details:

USN-5821-1 fixed a vulnerability in wheel and pip. Unfortunately,

it was missing a commit to fix it properly in pip.

We apologize for the inconvenience.

Original advisory details:

 Sebastian Chnelik discovered that wheel incorrectly handled

 certain file names when validated against a regex expression.

 An attacker could possibly use this issue to cause a

 denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   python3-pip                     22.2+dfsg-1ubuntu0.2
   python3-pip-whl                 22.2+dfsg-1ubuntu0.2

Ubuntu 22.04 LTS:
   python3-pip                     22.0.2+dfsg-1ubuntu0.2
   python3-pip-whl                 22.0.2+dfsg-1ubuntu0.2

Ubuntu 20.04 LTS:
   python-pip-whl                  20.0.2-5ubuntu1.8
   python3-pip                     20.0.2-5ubuntu1.8

Ubuntu 18.04 LTS:
   python-pip                      9.0.1-2.3~ubuntu1.18.04.7
   python-pip-whl                  9.0.1-2.3~ubuntu1.18.04.7
   python3-pip                     9.0.1-2.3~ubuntu1.18.04.7

Ubuntu 16.04 ESM:
   python-pip                      8.1.1-2ubuntu0.6+esm4
   python-pip-whl                  8.1.1-2ubuntu0.6+esm4
   python3-pip                     8.1.1-2ubuntu0.6+esm4

Ubuntu 14.04 ESM:
   python-pip                      1.5.4-1ubuntu4+esm3
   python-pip-whl                  1.5.4-1ubuntu4+esm3
   python3-pip                     1.5.4-1ubuntu4+esm3

In general, a standard system update will make all the necessary changes.

References

 

  https://ubuntu.com/security/notices/USN-5821-1

  CVE-2022-40898

Severity
important
Lowest
Low
Medium
High
Critical

February 28, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.