USN-7015-6: Python regressions

Published Nov 22, 2024
·
Updated

USN-7015-5 fixed vulnerabilities in python2.7. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the Python email module incorrectly parsed email addresses that contain special characters. A remote attacker could possibly use this issue to bypass certain protection mechanisms. (CVE-2023-27043) It was discovered that Python allowed excessive backtracking while parsing certain tarfile headers. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-6232) It was discovered that the Python email module incorrectly quoted newlines for email headers. A remote attacker could possibly use this issue to perform header injection. (CVE-2024-6923) It was discovered that the Python http.cookies module incorrectly handled parsing cookies that contained backslashes for quoted characters. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-7592) It was discovered that the Python zipfile module incorrectly handled certain malformed zip files. A remote attacker could possibly use this issue to cause Python to stop responding, resulting in a denial of service. (CVE-2024-8088)

Affected Software

20 affected componentsFixes available
All of the following
ubuntu/python2.7<2.7.18-13ubuntu1.4
2.7.18-13ubuntu1.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python2.7-minimal<2.7.18-13ubuntu1.4
2.7.18-13ubuntu1.4
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python2.7<2.7.18-1~20.04.6
2.7.18-1~20.04.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python2.7-minimal<2.7.18-1~20.04.6
2.7.18-1~20.04.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python2.7<2.7.17-1~18.04ubuntu1.13+esm8
2.7.17-1~18.04ubuntu1.13+esm8
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python2.7-minimal<2.7.17-1~18.04ubuntu1.13+esm8
2.7.17-1~18.04ubuntu1.13+esm8
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python2.7<2.7.12-1ubuntu0~16.04.18+esm13
2.7.12-1ubuntu0~16.04.18+esm13
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python2.7-minimal<2.7.12-1ubuntu0~16.04.18+esm13
2.7.12-1ubuntu0~16.04.18+esm13
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python2.7<2.7.6-8ubuntu0.6+esm22
2.7.6-8ubuntu0.6+esm22
Ubuntu Ubuntu=14.04
All of the following
ubuntu/python2.7-minimal<2.7.6-8ubuntu0.6+esm22
2.7.6-8ubuntu0.6+esm22
Ubuntu Ubuntu=14.04

Event History

Nov 22, 2024
Advisory Published
via Ubuntu·12:00 AM

Frequently Asked Questions

1

What vulnerabilities does USN-7015-6 address?

USN-7015-6 fixes minor regressions introduced in the previous update and corrects incorrect parsing of email addresses in the Python email module.

2

How do I fix the issues noted in USN-7015-6?

To mitigate the issues, update the Python packages to the recommended versions specified in the USN-7015-6 advisory.

3

What versions of Ubuntu are affected by USN-7015-6?

USN-7015-6 affects Ubuntu versions 14.04, 16.04, 18.04, 20.04, and 22.04.

4

Is USN-7015-6 applicable to Python 2.7 only on Ubuntu?

Yes, USN-7015-6 specifically addresses vulnerabilities in Python 2.7 on Ubuntu systems.

5

What is the significance of USN-7015-6 for Ubuntu users?

USN-7015-6 is significant as it resolves issues that could potentially impact email parsing functionality within applications relying on Python 2.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203