Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
tqdm could be made to crash or to allow arbitary code execution if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7216-1 January 16, 2025 tqdm vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: tqdm could be made to crash or to allow arbitary code execution if it received specially crafted input. Software Description: - tqdm: fast, extensible progress bar for Python 3 and CLI tool Details: It was discovered that tqdm did not properly sanitize non-boolean CLI Arguments. A local attacker could possibly use this issue to execute arbitrary code on the host. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-34062) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-tqdm 4.66.2-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-tqdm 4.57.0-2ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7216-1 CVE-2024-34062 . Ubuntu Security Notice USN-7217-1 relates to a vulnerabilities in the requests library that enable arbitrary command execution via specially designed input.. tqdm update, Ubuntu security, arbitrary code execution, Python progress bar, security advisory. . Severity: Critical. LinuxSecurity.com Team
tcmu could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4707-1 January 28, 2021 tcmu vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS Summary: tcmu could be made to crash if it received specially crafted input. Software Description: - tcmu: TCM-Userspace backend Details: It was discovered that TCMU lacked a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libtcmu2 1.5.2-5ubuntu0.20.10.1 tcmu-runner 1.5.2-5ubuntu0.20.10.1 Ubuntu 20.04 LTS: libtcmu2 1.5.2-5ubuntu0.20.04.1 tcmu-runner 1.5.2-5ubuntu0.20.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4707-1 CVE-2021-3139 Package Information: https://launchpad.net/ubuntu/+source/tcmu/1.5.2-5ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/tcmu/1.5.2-5ubuntu0.20.04.1 . Critical TCMU input issue could crash Ubuntu 20.10 and 20.04 LTS systems with crafted input, requiring urgent update.. TCMU Vulnerability, Ubuntu Update, Input Manipulation. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.