Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Waitress.
Software Description:
- waitress: production-quality pure-Python WSGI server
Details:
It was discovered that Waitress could process follow up requests when
receiving a specially crafted message. An attacker could use this issue to
have the server process inconsistent client requests. (CVE-2024-49768)
Dylan Jay discovered that Waitress could be lead to write to an unexisting
socket after closing the remote connection. An attacker could use this
issue to increase resource utilization leading to a denial of service.
(CVE-2024-49769)
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 python3-waitress 3.0.0-1ubuntu0.1 Ubuntu 24.04 LTS python3-waitress 2.1.2-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-waitress 1.4.4-1.1ubuntu1.1 Ubuntu 20.04 LTS python3-waitress 1.4.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-7115-1
CVE-2024-49768, CVE-2024-49769
Get the latest Linux and open source security news straight to your inbox.