Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 22.10, 22.04 LTS USN-5960-1 Moderate: Python Bypass Threat

ubuntu
Calendar Grey March 20, 2023
Scroller Ubuntu
Crucial security patch released for Python on various Ubuntu versions, targeting possible URL redirection flaws.
Python could be made to bypass blocklisting methods if a specially crafted URL was provided.

Summary

Python could be made to bypass blocklisting methods if a specially

crafted URL was provided.

Software Description:

- python3.10: An interactive high-level object-oriented language

- python3.8: An interactive high-level object-oriented language

- python2.7: An interactive high-level object-oriented language

- python3.6: An interactive high-level object-oriented language

- python3.5: An interactive high-level object-oriented language

Details:

Yebo Cao discovered that Python incorrectly handled certain URLs.

An attacker could possibly use this issue to bypass blocklisting

methods by supplying a URL that starts with blank characters.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
  python3.10                      3.10.7-1ubuntu0.3

Ubuntu 22.04 LTS:
  python3.10                      3.10.6-1~22.04.2ubuntu1

Ubuntu 20.04 LTS:
  python3.8                       3.8.10-0ubuntu1~20.04.7

Ubuntu 18.04 LTS:
  python2.7                       2.7.17-1~18.04ubuntu1.11
  python3.6                       3.6.9-1~18.04ubuntu1.12

Ubuntu 16.04 ESM:
  python2.7                       2.7.12-1ubuntu0~16.04.18+esm4
  python3.5                       3.5.2-2ubuntu0~16.04.13+esm7

Ubuntu 14.04 ESM:
  python2.7                       2.7.6-8ubuntu0.6+esm14

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5960-1

CVE-2023-24329

Severity
important
Lowest
Low
Medium
High
Critical

March 16, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.