Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
tqdm could be made to crash or to allow arbitary code execution if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7216-1 January 16, 2025 tqdm vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: tqdm could be made to crash or to allow arbitary code execution if it received specially crafted input. Software Description: - tqdm: fast, extensible progress bar for Python 3 and CLI tool Details: It was discovered that tqdm did not properly sanitize non-boolean CLI Arguments. A local attacker could possibly use this issue to execute arbitrary code on the host. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-34062) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-tqdm 4.66.2-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-tqdm 4.57.0-2ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7216-1 CVE-2024-34062 . Ubuntu Security Notice USN-7217-1 relates to a vulnerabilities in the requests library that enable arbitrary command execution via specially designed input.. tqdm update, Ubuntu security, arbitrary code execution, Python progress bar, security advisory. . Severity: Critical. LinuxSecurity.com Team
A vulnerability in tqdm could allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201807-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: tqdm: Arbitrary code execution Date: July 18, 2018 Bugs: #636384 ID: 201807-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in tqdm could allow remote attackers to execute arbitrary code. Background ========= tqdm is a smart progress meter. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/tqdm < 4.23.3 > = 4.23.3 Description ========== A vulnerablility was discovered in tqdm._version that could allow a malicious git log within the current working directory. Impact ===== A remote attacker could execute arbitrary commands by enticing a user to clone a crafted repo. Workaround ========= There is no known workaround at this time. Resolution ========= All tqdm users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/tqdm-4.23.3" References ========= [ 1 ] CVE-2016-10075 https://nvd.nist.gov/vuln/detail/CVE-2016-10075 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201807-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concernsshould be addressed to
Get the latest Linux and open source security news straight to your inbox.