First published: Thu Sep 19 2024(Updated: )
USN-7015-1 fixed several vulnerabilities in Python. This update provides one of the corresponding updates for python2.7 for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and a second for python3.5 for Ubuntu 16.04 LTS. Original advisory details: It was discovered that Python allowed excessive backtracking while parsing certain tarfile headers. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. This issue only affected python3.5 for Ubuntu 16.04 LTS (CVE-2024-6232) It was discovered that the Python http.cookies module incorrectly handled parsing cookies that contained backslashes for quoted characters. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-7592)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python2.7 | <2.7.18-13ubuntu1.2+esm2 | 2.7.18-13ubuntu1.2+esm2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.18-13ubuntu1.2+esm2 | 2.7.18-13ubuntu1.2+esm2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python2.7 | <2.7.18-1~20.04.4+esm2 | 2.7.18-1~20.04.4+esm2 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.18-1~20.04.4+esm2 | 2.7.18-1~20.04.4+esm2 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python2.7 | <2.7.17-1~18.04ubuntu1.13+esm5 | 2.7.17-1~18.04ubuntu1.13+esm5 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.17-1~18.04ubuntu1.13+esm5 | 2.7.17-1~18.04ubuntu1.13+esm5 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python2.7 | <2.7.12-1ubuntu0~16.04.18+esm10 | 2.7.12-1ubuntu0~16.04.18+esm10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python2.7-minimal | <2.7.12-1ubuntu0~16.04.18+esm10 | 2.7.12-1ubuntu0~16.04.18+esm10 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5 | <3.5.2-2ubuntu0~16.04.13+esm14 | 3.5.2-2ubuntu0~16.04.13+esm14 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/python3.5-minimal | <3.5.2-2ubuntu0~16.04.13+esm14 | 3.5.2-2ubuntu0~16.04.13+esm14 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.