Python could be made to bypass blocklisting methods if a specially crafted URL was provided.. =========================================================================Ubuntu Security Notice USN-5960-1 March 16, 2023 python2.7, python3.10, python3.5, python3.6, python3.8 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Python could be made to bypass blocklisting methods if a specially crafted URL was provided. Software Description: - python3.10: An interactive high-level object-oriented language - python3.8: An interactive high-level object-oriented language - python2.7: An interactive high-level object-oriented language - python3.6: An interactive high-level object-oriented language - python3.5: An interactive high-level object-oriented language Details: Yebo Cao discovered that Python incorrectly handled certain URLs. An attacker could possibly use this issue to bypass blocklisting methods by supplying a URL that starts with blank characters. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3.10 3.10.7-1ubuntu0.3 Ubuntu 22.04 LTS: python3.10 3.10.6-1~22.04.2ubuntu1 Ubuntu 20.04 LTS: python3.8 3.8.10-0ubuntu1~20.04.7 Ubuntu 18.04 LTS: python2.7 2.7.17-1~18.04ubuntu1.11 python3.6 3.6.9-1~18.04ubuntu1.12 Ubuntu 16.04 ESM: python2.7 2.7.12-1ubuntu0~16.04.18+esm4 python3.5 3.5.2-2ubuntu0~16.04.13+esm7 Ubuntu 14.04 ESM: python2.7 2.7.6-8ubuntu0.6+esm14 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5960-1 CVE-2023-24329 Package Information: https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.3 https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.2ubuntu1 https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.7 https://launchpad.net/ubuntu/+source/python2.7/2.7.17-1~18.04ubuntu1.11 https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.12 . Crucial security patch released for Python on various Ubuntu versions, targeting possible URL redirection flaws.. Python Security Issue, Ubuntu Python Update, Bypass Threat, URL Exploit. . Severity: Important. LinuxSecurity.com Team
An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806). . MGASA-2019-0051 - Updated pdns-recursor package fixes security vulnerabilities Publication date: 23 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0051.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-3806, CVE-2019-3807 An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806). An issue has been found in PowerDNS Recursor where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation (CVE-2019-3807). References: - https://bugs.mageia.org/show_bug.cgi?id=24218 - https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html - https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html - https://www.cve.org/CVERecord?id=CVE-2019-3806 - https://www.cve.org/CVERecord?id=CVE-2019-3807 SRPMS: - 6/core/pdns-recursor-4.1.9-1.mga6 . PowerDNS Recursor resolves critical vulnerabilities in Mageia influencing DNS configurations. Learn about the remedies in MGASA-2019-0051.. PowerDNS Recursor Security, Mageia Security Update, DNSSEC Vulnerability Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.