USN-7040-2: ConfigObj vulnerability
USN-7040-1 fixed a vulnerability in ConfigObj. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that ConfigObj contains regex that is susceptible to catastrophic backtracking. An attacker could possibly use this issue to cause a regular expression denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7040-2?
USN-7040-2 addresses a vulnerability in ConfigObj that can lead to catastrophic backtracking, posing a security risk.
How do I fix USN-7040-2?
To fix USN-7040-2, you should upgrade the python-configobj package to version 4.7.2+ds-5ubuntu0.1~esm1.
What versions of Ubuntu are affected by USN-7040-2?
USN-7040-2 affects Ubuntu 14.04 LTS systems that utilize the vulnerable python-configobj package.
Is USN-7040-2 a critical vulnerability?
While not categorized as critical, the vulnerability addressed in USN-7040-2 can be exploited under specific conditions, making it important to apply the update.
What actions should users take regarding USN-7040-2?
Users should ensure they have installed the latest updates for the affected python-configobj package to mitigate the vulnerability.