USN-1314-1: Python 3 vulnerabilities
Giampaolo Rodola discovered that the smtpd module in Python 3 did not properly handle certain error conditions. A remote attacker could exploit this to cause a denial of service via daemon outage. This issue only affected Ubuntu 10.04 LTS. (CVE-2010-3493) Niels Heinen discovered that the urllib module in Python 3 would process Location headers that specify a file:// URL. A remote attacker could use this to obtain sensitive information or cause a denial of service via resource consumption. (CVE-2011-1521)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-1314-1?
USN-1314-1 has a severity of moderate.
How does the smtpd module vulnerability in Python 3 impact Ubuntu 10.04 LTS?
The smtpd module vulnerability in Python 3 can cause a denial of service via daemon outage on Ubuntu 10.04 LTS.
What is the remedy for the smtpd module vulnerability in Python 3 affecting Ubuntu 10.04 LTS?
The remedy for the smtpd module vulnerability in Python 3 affecting Ubuntu 10.04 LTS is to update the python3.1-minimal package to version 3.1.3-1ubuntu1.1 or later.
What is the impact of the urllib module vulnerability in Python 3 on Ubuntu 11.04?
The urllib module vulnerability in Python 3 does not affect Ubuntu 11.04.
What are the remediation steps for the urllib module vulnerability in Python 3 affecting Ubuntu 11.04?
No remediation steps are required for the urllib module vulnerability in Python 3 as it does not affect Ubuntu 11.04.