USN-6991-1: AIOHTTP vulnerability
Published Sep 5, 2024
·Updated
It was discovered that AIOHTTP did not properly restrict file access when the 'followsymlinks' option was set to True. A remote attacker could possibly use this issue to access unauthorized files on the system.
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/python-aiohttp-doc<3.9.1-1ubuntu0.1
3.9.1-1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3-aiohttp<3.9.1-1ubuntu0.1
3.9.1-1ubuntu0.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python-aiohttp-doc<3.8.1-4ubuntu0.2
3.8.1-4ubuntu0.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-aiohttp<3.8.1-4ubuntu0.2
3.8.1-4ubuntu0.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-aiohttp<3.6.2-1ubuntu1+esm3
3.6.2-1ubuntu1+esm3
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python3-aiohttp<3.0.1-1ubuntu0.1~esm4
3.0.1-1ubuntu0.1~esm4
Ubuntu Ubuntu=18.04
Event History
Sep 5, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6991-1?
The severity of USN-6991-1 is categorized as a potential unauthorized file access vulnerability.
2
How do I fix USN-6991-1?
To fix USN-6991-1, update your aiohttp packages to the recommended versions provided in the advisory.
3
What products are affected by USN-6991-1?
USN-6991-1 affects aiohttp packages on Ubuntu versions 18.04, 20.04, 22.04, and 24.04.
4
What is the root cause of USN-6991-1?
USN-6991-1 is caused by improper restriction of file access when the 'follow_symlinks' option is enabled.
5
Who can be impacted by USN-6991-1?
Developers and system administrators using vulnerable versions of aiohttp in their applications can be impacted by USN-6991-1.