Ubuntu alert USN-8018-3 (python2.7)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8018-3] Python 2.7 vulnerabilities | |
| Date: | Thu, 19 Mar 2026 12:05:02 +0000 | |
| Message-ID: | <E1w3C7a-0007g3-Ji@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8018-3 March 19, 2026 python2.7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in python2.7 Software Description: - python2.7: An interactive high-level object-oriented language Details: USN-8018-1 fixed CVE-2025-12084, CVE-2025-15282, CVE-2026-0672, CVE-2026-0865 for python3. This update provides the corresponding updates for python2.7. Original advisory details: Denis Ledoux discovered that Python incorrectly parsed email message headers. An attacker could possibly use this issue to inject arbitrary headers into email messages. This issue only affected python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-11468) Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python inefficiently parsed XML input with quadratic complexity. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-12084) It was discovered that Python incorrectly parsed malicious plist files. An attacker could possibly use this issue to cause Python to use excessive resources, leading to a denial of service. This issue only affected python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-13837) Omar Hasan discovered that Python incorrectly parsed URL mediatypes. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2025-15282) Omar Hasan discovered that Python incorrectly parsed malicious IMAP inputs. An attacker could possibly use this issue to inject arbitrary IMAP commands. (CVE-2025-15366) Omar Hasan discovered that Python incorrectly parsed malicious POP3 inputs. An attacker could possibly use this issue to inject arbitrary POP3 commands. (CVE-2025-15367) Omar Hasan discovered that Python incorrectly parsed malicious HTTP cookie headers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0672) Omar Hasan discovered that Python incorrectly parsed malicious HTTP header names and values. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0865) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libpython2.7 2.7.18-13ubuntu1.5+esm8 Available with Ubuntu Pro python2.7 2.7.18-13ubuntu1.5+esm8 Available with Ubuntu Pro Ubuntu 20.04 LTS libpython2.7 2.7.18-1~20.04.7+esm9 Available with Ubuntu Pro python2.7 2.7.18-1~20.04.7+esm9 Available with Ubuntu Pro Ubuntu 18.04 LTS libpython2.7 2.7.17-1~18.04ubuntu1.13+esm14 Available with Ubuntu Pro python2.7 2.7.17-1~18.04ubuntu1.13+esm14 Available with Ubuntu Pro Ubuntu 16.04 LTS libpython2.7 2.7.12-1ubuntu0~16.04.18+esm19 Available with Ubuntu Pro python2.7 2.7.12-1ubuntu0~16.04.18+esm19 Available with Ubuntu Pro Ubuntu 14.04 LTS libpython2.7 2.7.6-8ubuntu0.6+esm29 Available with Ubuntu Pro python2.7 2.7.6-8ubuntu0.6+esm29 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8018-3 https://ubuntu.com/security/notices/USN-8018-2 https://ubuntu.com/security/notices/USN-8018-1 CVE-2025-12084, CVE-2025-15282, CVE-2026-0672, CVE-2026-0865
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmm72BcACgkQcpJm3tlz hgFArg/9HokOy+OticStU8MbLQlN2t0BNdfrbX0pyHFpsYUgeI9hpmfyP7QeSgrk sl6VMeY1vyC7n52Rh4EI1z+2DU8bNnEsBlUGXs9cqP/LaDL1d56k4/86Bw0g0a2Y 6OpXJrbgP8Fmy/44zxg8INdvwT3cZgz7nf8Dd0nxm9qcNk+LRPBpZcCqPlbDU2xh lvsfvjciD7ex8DDiGdvaloLcIK0O+tQWmIN1T6i9hlzWLpsIoEWZFDteyQOkuakt gFiHjPUoABoTQkgbEGDGe06R8tDiIxpPrrDePxCbo9cOnzSYXCMlWRPyyqkHdgAy bYjxcNHIpAzYnPV2knCE0UdBSiBk+/Y9BGnTtRuvLjY2fV9SC7DSzckQGLj7Yle9 MHCUbb9JjMBsAOyI7gcbvPpy8sywxWD6rUq1gxtEFVurQ22SFEd+rBF7htJRJTDA 5tJJARZ2gdUeCGWXRl3rxqoKK41yGFyTKStxpldDeZ7KhCDudtIRp5nejbH2VBa6 g4f+rja5gaD6ytkfRwrEv4oSYzLzxN6l+wKJH3w/pfuD4S6yQxzHYD8knivABFbW Hl3L5+uDZBMRMQnJE196deYNQVD6vsae+/IaZuc45cd6JWll0RhbhEegA9WI1QeN Ylsz+F4s2OZnjgPvbR/lkJ59BGDSDiAvsIbVjwO3pDNmWGCXYLU= =toAB -----END PGP SIGNATURE-----
