First published: Wed Oct 14 2020(Updated: )
It was discovered that Python incorrectly handled certain character sequences. A remote attacker could possibly use this issue to perform CRLF injection.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python2.7 | <2.7.17-1~18.04ubuntu1.2 | 2.7.17-1~18.04ubuntu1.2 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.17-1~18.04ubuntu1.2 | 2.7.17-1~18.04ubuntu1.2 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3.6 | <3.6.9-1~18.04ubuntu1.3 | 3.6.9-1~18.04ubuntu1.3 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3.6-minimal | <3.6.9-1~18.04ubuntu1.3 | 3.6.9-1~18.04ubuntu1.3 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7 | <2.7.12-1ubuntu0~16.04.13 | 2.7.12-1ubuntu0~16.04.13 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.12-1ubuntu0~16.04.13 | 2.7.12-1ubuntu0~16.04.13 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5 | <3.5.2-2ubuntu0~16.04.12 | 3.5.2-2ubuntu0~16.04.12 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5-minimal | <3.5.2-2ubuntu0~16.04.12 | 3.5.2-2ubuntu0~16.04.12 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7 | <2.7.6-8ubuntu0.6+esm7 | 2.7.6-8ubuntu0.6+esm7 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.6-8ubuntu0.6+esm7 | 2.7.6-8ubuntu0.6+esm7 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python3.4 | <3.4.3-1ubuntu1~14.04.7+esm8 | 3.4.3-1ubuntu1~14.04.7+esm8 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python3.4-minimal | <3.4.3-1ubuntu1~14.04.7+esm8 | 3.4.3-1ubuntu1~14.04.7+esm8 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/python2.7 | <2.7.3-0ubuntu3.19 | 2.7.3-0ubuntu3.19 |
Ubuntu Ubuntu | =12.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.3-0ubuntu3.19 | 2.7.3-0ubuntu3.19 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Python vulnerability is USN-4581-1.
This vulnerability allows a remote attacker to perform CRLF injection.
The affected versions of Python are 2.7.17-1~18.04ubuntu1.2, 3.6.9-1~18.04ubuntu1.3, 2.7.12-1ubuntu0~16.04.13, 3.5.2-2ubuntu0~16.04.12, 2.7.6-8ubuntu0.6+esm7, 3.4.3-1ubuntu1~14.04.7+esm8, and 2.7.3-0ubuntu3.19.
To fix this vulnerability, update Python to version 2.7.17-1~18.04ubuntu1.2, 3.6.9-1~18.04ubuntu1.3, 2.7.12-1ubuntu0~16.04.13, 3.5.2-2ubuntu0~16.04.12, 2.7.6-8ubuntu0.6+esm7, 3.4.3-1ubuntu1~14.04.7+esm8, or 2.7.3-0ubuntu3.19.
You can find more information about this vulnerability at the following references: [USN-4754-3](https://ubuntu.com/security/notices/USN-4754-3) and [CVE-2020-26116](https://ubuntu.com/security/CVE-2020-26116).