USN-7160-1: Mpmath vulnerability
Published Dec 15, 2024
·Updated
It was discovered Mpmath incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause Mpmath to consume resources, leading to a denial of service.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/python3-mpmath<1.1.0-2ubuntu0.1~esm1
1.1.0-2ubuntu0.1~esm1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python-mpmath<1.0.0-1ubuntu0.1~esm1
1.0.0-1ubuntu0.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python3-mpmath<1.0.0-1ubuntu0.1~esm1
1.0.0-1ubuntu0.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-mpmath<0.19-3ubuntu0.1~esm1
0.19-3ubuntu0.1~esm1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python3-mpmath<0.19-3ubuntu0.1~esm1
0.19-3ubuntu0.1~esm1
Ubuntu Ubuntu=16.04
Event History
Dec 15, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7160-1?
The severity of USN-7160-1 is classified as a denial of service vulnerability.
2
How do I fix USN-7160-1?
You can fix USN-7160-1 by upgrading the affected packages to the specified versions as mentioned in the advisory.
3
Which Ubuntu versions are affected by USN-7160-1?
USN-7160-1 affects Ubuntu 20.04, 18.04, and 16.04 with specific versions of python-mpmath and python3-mpmath.
4
Can USN-7160-1 be exploited remotely?
Yes, an attacker could potentially exploit USN-7160-1 to perform a denial of service remotely.
5
What are the affected packages in USN-7160-1?
The affected packages in USN-7160-1 include python3-mpmath and python-mpmath for various Ubuntu versions.