USN-7002-1: Setuptools vulnerability
Published Sep 12, 2024
·Updated
It was discovered that setuptools was vulnerable to remote code execution. An attacker could possibly use this issue to execute arbitrary code.
Affected Software
30 affected componentsFixes available
All of the following
ubuntu/python3-setuptools<68.1.2-2ubuntu1.1
68.1.2-2ubuntu1.1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/pypy-setuptools<44.1.1-1.2ubuntu0.22.04.1+esm1
44.1.1-1.2ubuntu0.22.04.1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python-setuptools<44.1.1-1.2ubuntu0.22.04.1+esm1
44.1.1-1.2ubuntu0.22.04.1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-setuptools<59.6.0-1.2ubuntu0.22.04.2
59.6.0-1.2ubuntu0.22.04.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/pypy-setuptools<44.0.0-2ubuntu0.1+esm1
44.0.0-2ubuntu0.1+esm1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python-setuptools<44.0.0-2ubuntu0.1+esm1
44.0.0-2ubuntu0.1+esm1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python3-setuptools<45.2.0-1ubuntu0.2
45.2.0-1ubuntu0.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/pypy-setuptools<39.0.1-2ubuntu0.1+esm1
39.0.1-2ubuntu0.1+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-setuptools<39.0.1-2ubuntu0.1+esm1
39.0.1-2ubuntu0.1+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python3-setuptools<39.0.1-2ubuntu0.1+esm1
39.0.1-2ubuntu0.1+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/pypy-setuptools<20.7.0-1ubuntu0.1~esm2
20.7.0-1ubuntu0.1~esm2
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python-setuptools<20.7.0-1ubuntu0.1~esm2
20.7.0-1ubuntu0.1~esm2
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python3-setuptools<20.7.0-1ubuntu0.1~esm2
20.7.0-1ubuntu0.1~esm2
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python-setuptools<3.3-1ubuntu2+esm2
3.3-1ubuntu2+esm2
Ubuntu Ubuntu=14.04
All of the following
ubuntu/python3-setuptools<3.3-1ubuntu2+esm2
3.3-1ubuntu2+esm2
Ubuntu Ubuntu=14.04
Event History
Sep 12, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7002-1?
The severity of USN-7002-1 is considered high due to the risk of remote code execution.
2
How do I fix USN-7002-1?
You can fix USN-7002-1 by upgrading to the specified patched versions of python3-setuptools, pypy-setuptools, or python-setuptools, depending on your Ubuntu release.
3
Which Ubuntu versions are affected by USN-7002-1?
USN-7002-1 affects multiple versions of Ubuntu including 14.04, 16.04, 18.04, 20.04, 22.04, and 24.04.
4
What packages are vulnerable in USN-7002-1?
The vulnerable packages in USN-7002-1 include python3-setuptools, pypy-setuptools, and python-setuptools.
5
Is remote code execution possible with USN-7002-1?
Yes, the vulnerability identified in USN-7002-1 allows attackers to execute arbitrary code remotely.