-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAme3ro8FAwAAAAAACgkQZWnYVadEvpPC
2hAAvR1mqNQUJiwsNoOQG3YnGuXN27A5pf8O0qcUelXHHIkryOye4YXo8h1j5mjyMkAjMMxnQR/Q
TXQu6Cq8YDE4Zpk93rU4on+zpa5Z4HulvJnoMXi6+iCmXvu3K+/lxYnLFCYk0a+d6RJ0se+MOOif
LxOXd2v4oFsjNJDpTZJ43PjKPIqd13LdFXr8NJf/vsPM6agS9uLvZU2KrWgf0wmRoQ4efVySiUNo
+Qie3+noh6kLU40HyXQvM+GZTcxqG2vsfxXgNVcxzWHMEiwClf/HIPptUn8bhvmkH7r462fPNGOq
XpkiKWQqsLmx+C7Ka8wb9v+8JdYDZlPKwUyvfFaZ5L+S7Ej+Z6oOhRdmVpGmYY/jKWt1TYixsQ7C
JBcB2HuGRHHyxvF3NguktcgR75YkObFM2CV62lR1do0Qzd7BR9s4rwOwldmX0yaLF0X/HilI10KB
Tnglde5QOKkBQDcXMPVicKu3DrPa2IRic4q6bR8UXPzU0ZYISWK8zub3EGkbMH741kQcKfS1fYvl
VtzKzBe2WcjUG6NyXkPjDSdIJbSEE405/ILYCSkkC1UbB/hF+zrKQ6vLLgS6T/3c2jEBT7pA0PA/
03E2t4dsSgIIH+EunxOz+ePgdouHO+5iNA5ldMXF0qNM2fsIjZPAewCBsGiCfRrtCR28GeqN6rb4
v5o=
=FOId
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7280-1
February 20, 2025
python3.10, python3.12, python3.8 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Python could allow Server-Side Request Forgery attacks.
Software Description:
- python3.12: An interactive high-level object-oriented language
- python3.10: An interactive high-level object-oriented language
- python3.8: An interactive high-level object-oriented language
Details:
It was discovered that Python incorrectly handled parsing domain names that
included square brackets. A remote attacker could possibly use this issue
to perform a Server-Side Request Forgery (SSRF) attack.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.10
python3.12 3.12.7-1ubuntu2
python3.12-minimal 3.12.7-1ubuntu2
Ubuntu 24.04 LTS
python3.12 3.12.3-1ubuntu0.5
python3.12-minimal 3.12.3-1ubuntu0.5
Ubuntu 22.04 LTS
python3.10 3.10.12-1~22.04.9
python3.10-minimal 3.10.12-1~22.04.9
Ubuntu 20.04 LTS
python3.8 3.8.10-0ubuntu1~20.04.15
python3.8-minimal 3.8.10-0ubuntu1~20.04.15
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-7280-1
CVE-2025-0938
Package Information:
https://launchpad.net/ubuntu/+source/python3.12/3.12.7-1ubuntu2
https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.5
https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.9
https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.15
No comments:
Post a Comment