First published: Thu Mar 16 2023(Updated: )
Yebo Cao discovered that Python incorrectly handled certain URLs. An attacker could possibly use this issue to bypass blocklisting methods by supplying a URL that starts with blank characters.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3.10 | <3.10.7-1ubuntu0.3 | 3.10.7-1ubuntu0.3 |
Ubuntu Ubuntu | =22.10 | |
All of | ||
ubuntu/python3.10 | <3.10.6-1~22.04.2ubuntu1 | 3.10.6-1~22.04.2ubuntu1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python3.8 | <3.8.10-0ubuntu1~20.04.7 | 3.8.10-0ubuntu1~20.04.7 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python2.7 | <2.7.17-1~18.04ubuntu1.11 | 2.7.17-1~18.04ubuntu1.11 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3.6 | <3.6.9-1~18.04ubuntu1.12 | 3.6.9-1~18.04ubuntu1.12 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7 | <2.7.12-1ubuntu0~16.04.18+esm4 | 2.7.12-1ubuntu0~16.04.18+esm4 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5 | <3.5.2-2ubuntu0~16.04.13+esm7 | 3.5.2-2ubuntu0~16.04.13+esm7 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7 | <2.7.6-8ubuntu0.6+esm14 | 2.7.6-8ubuntu0.6+esm14 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Python vulnerability is USN-5960-1.
The Python vulnerability allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
The following versions of Python are affected: Python 3.10.7-1ubuntu0.3, Python 3.10.6-1~22.04.2ubuntu1, Python 3.8.10-0ubuntu1~20.04.7, Python 2.7.17-1~18.04ubuntu1.11, Python 3.6.9-1~18.04ubuntu1.12, Python 2.7.12-1ubuntu0~16.04.18+esm4, Python 3.5.2-2ubuntu0~16.04.13+esm7, Python 2.7.6-8ubuntu0.6+esm14.
An attacker can exploit this vulnerability by supplying a URL that starts with blank characters.
You can find more information about fixing this vulnerability at the following references: [CVE-2023-24329](https://ubuntu.com/security/CVE-2023-24329), [USN-5888-1](https://ubuntu.com/security/notices/USN-5888-1), [USN-6139-1](https://ubuntu.com/security/notices/USN-6139-1).