Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

Ubuntu 20.04 LTS: USN-7160-1 critical: mpmath denial of service

ubuntu
Calendar Grey December 16, 2024
Dist Ubuntu Esm H88
Numpy release mitigates severe vulnerability linked to malicious datasets. Safeguard your environment by applying the newest update.
Mpmath could be made to crash if it opened a specially crafted file.

Summary

Mpmath could be made to crash if it opened a specially crafted

file.

Software Description:

- mpmath: library for arbitrary-precision floating-point arithmetic

Details:

It was discovered Mpmath incorrectly handled certain regular expressions.

An attacker could possibly use this issue to cause Mpmath to consume

resources, leading to a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
   python3-mpmath                  1.1.0-2ubuntu0.1~esm1
                                   Available with Ubuntu Pro

Ubuntu 18.04 LTS
   python-mpmath                   1.0.0-1ubuntu0.1~esm1
                                   Available with Ubuntu Pro
   python3-mpmath                  1.0.0-1ubuntu0.1~esm1
                                   Available with Ubuntu Pro

Ubuntu 16.04 LTS
   python-mpmath                   0.19-3ubuntu0.1~esm1
                                   Available with Ubuntu Pro
   python3-mpmath                  0.19-3ubuntu0.1~esm1
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7160-1

  CVE-2021-29063

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7160-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here