USN-6771-1: SQL parse vulnerability
Published May 13, 2024
·Updated
It was discovered that SQL parse incorrectly handled certain nested lists. An attacker could possibly use this issue to cause a denial of service.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/python3-sqlparse<0.4.4-1ubuntu0.1
0.4.4-1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3-sqlparse<0.4.2-1ubuntu1.1
0.4.2-1ubuntu1.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/python3-sqlparse<0.4.2-1ubuntu0.22.04.2
0.4.2-1ubuntu0.22.04.2
Ubuntu Ubuntu=22.04
Event History
May 13, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6771-1?
The severity of USN-6771-1 is categorized as a potential denial of service vulnerability.
2
How do I fix USN-6771-1?
To fix USN-6771-1, update the python3-sqlparse package to the latest version available for your Ubuntu release.
3
Which versions of Ubuntu are affected by USN-6771-1?
USN-6771-1 affects Ubuntu versions 24.04, 23.10, and 22.04 that have specific vulnerable versions of python3-sqlparse.
4
What is the vulnerability caused by USN-6771-1?
USN-6771-1 is caused by improper handling of certain nested lists in SQL parse that could be exploited for denial of service.
5
Is there a workaround for USN-6771-1 if I cannot update immediately?
There is no known workaround for USN-6771-1, thus it is recommended to update to a secure version as soon as possible.