USN-7216-1: tqdm vulnerability
Published Jan 16, 2025
·Updated
It was discovered that tqdm did not properly sanitize non-boolean CLI Arguments. A local attacker could possibly use this issue to execute arbitrary code on the host. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-34062)
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/python3-tqdm<4.66.2-2ubuntu0.1~esm1
4.66.2-2ubuntu0.1~esm1
Ubuntu Ubuntu=24.04
All of the following
ubuntu/python3-tqdm<4.57.0-2ubuntu0.1~esm2
4.57.0-2ubuntu0.1~esm2
Ubuntu Ubuntu=22.04
Event History
Jan 16, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7216-1?
The severity of USN-7216-1 is critical as it allows local attackers to execute arbitrary code.
2
How do I fix USN-7216-1?
To fix USN-7216-1, update python3-tqdm to version 4.66.2-2ubuntu0.1~esm1 for Ubuntu 24.04 or 4.57.0-2ubuntu0.1~esm2 for Ubuntu 22.04.
3
Which systems are affected by USN-7216-1?
USN-7216-1 affects Ubuntu 22.04 LTS and Ubuntu 24.04 LTS specifically.
4
What is the cause of vulnerability USN-7216-1?
The vulnerability USN-7216-1 is caused by improper sanitization of non-boolean CLI arguments in tqdm.
5
Can USN-7216-1 be exploited remotely?
No, USN-7216-1 cannot be exploited remotely; it requires local access to the system.