First published: Tue Apr 21 2020(Updated: )
It was discovered that Python incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. (CVE-2019-18348) It was discovered that Python incorrectly handled certain HTTP requests. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-8492)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3.7 | <3.7.5-2~19.10ubuntu1 | 3.7.5-2~19.10ubuntu1 |
Ubuntu Ubuntu | =19.10 | |
All of | ||
ubuntu/python3.7-minimal | <3.7.5-2~19.10ubuntu1 | 3.7.5-2~19.10ubuntu1 |
Ubuntu Ubuntu | =19.10 | |
All of | ||
ubuntu/python2.7 | <2.7.17-1~18.04ubuntu1 | 2.7.17-1~18.04ubuntu1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.17-1~18.04ubuntu1 | 2.7.17-1~18.04ubuntu1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3.6 | <3.6.9-1~18.04ubuntu1 | 3.6.9-1~18.04ubuntu1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3.6-minimal | <3.6.9-1~18.04ubuntu1 | 3.6.9-1~18.04ubuntu1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7 | <2.7.12-1ubuntu0~16.04.11 | 2.7.12-1ubuntu0~16.04.11 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.12-1ubuntu0~16.04.11 | 2.7.12-1ubuntu0~16.04.11 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5 | <3.5.2-2ubuntu0~16.04.10 | 3.5.2-2ubuntu0~16.04.10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5-minimal | <3.5.2-2ubuntu0~16.04.10 | 3.5.2-2ubuntu0~16.04.10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7 | <2.7.6-8ubuntu0.6+esm5 | 2.7.6-8ubuntu0.6+esm5 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.6-8ubuntu0.6+esm5 | 2.7.6-8ubuntu0.6+esm5 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python3.4 | <3.4.3-1ubuntu1~14.04.7+esm6 | 3.4.3-1ubuntu1~14.04.7+esm6 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python3.4-minimal | <3.4.3-1ubuntu1~14.04.7+esm6 | 3.4.3-1ubuntu1~14.04.7+esm6 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python2.7 | <2.7.3-0ubuntu3.17 | 2.7.3-0ubuntu3.17 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.3-0ubuntu3.17 | 2.7.3-0ubuntu3.17 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Python vulnerabilities is CVE-2019-18348.
The Python vulnerabilities could allow a remote attacker to perform CRLF injection and cause a denial of service.
The vulnerabilities affect Python versions 2.7, 3.4, 3.5, 3.6, and 3.7.
To fix the Python vulnerabilities, update your Python packages to the specified remedial versions.
You can find more information about the Python vulnerabilities in the provided references.