|
|
Subscribe / Log in / New account

Ubuntu alert USN-6473-2 (python-pip)

From:  Jorge Sancho Larraz <jorge.sancho.larraz@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-6473-2] pip vulnerabilities
Date:  Wed, 15 Nov 2023 14:22:29 +0100
Message-ID:  <4959653f-7e88-46a1-9b89-7590a5ace147@canonical.com>

========================================================================== Ubuntu Security Notice USN-6473-2 November 15, 2023 python-pip vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in pip. Software Description: - python-pip: Python package installer Details: USN-6473-1 fixed vulnerabilities in urllib3. This update provides the corresponding updates for the urllib3 module bundled into pip. Original advisory details:  It was discovered that urllib3 didn't strip HTTP Authorization header  on cross-origin redirects. A remote attacker could possibly use this  issue to obtain sensitive information. This issue only affected  Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)  It was discovered that urllib3 didn't strip HTTP Cookie header on  cross-origin redirects. A remote attacker could possibly use this  issue to obtain sensitive information. (CVE-2023-43804)  It was discovered that urllib3 didn't strip HTTP body on status code  303 redirects under certain circumstances. A remote attacker could  possibly use this issue to obtain sensitive information. (CVE-2023-45803) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10:   python3-pip                     23.2+dfsg-1ubuntu0.1   python3-pip-whl                 23.2+dfsg-1ubuntu0.1 Ubuntu 23.04:   python3-pip                     23.0.1+dfsg-1ubuntu0.2   python3-pip-whl                 23.0.1+dfsg-1ubuntu0.2 Ubuntu 22.04 LTS:   python3-pip                     22.0.2+dfsg-1ubuntu0.4   python3-pip-whl                 22.0.2+dfsg-1ubuntu0.4 Ubuntu 20.04 LTS:   python-pip-whl                  20.0.2-5ubuntu1.10   python3-pip                     20.0.2-5ubuntu1.10 Ubuntu 18.04 LTS (Available with Ubuntu Pro):   python-pip                      9.0.1-2.3~ubuntu1.18.04.8+esm2   python-pip-whl                  9.0.1-2.3~ubuntu1.18.04.8+esm2   python3-pip                     9.0.1-2.3~ubuntu1.18.04.8+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro):   python-pip                      8.1.1-2ubuntu0.6+esm6   python-pip-whl                  8.1.1-2ubuntu0.6+esm6   python3-pip                     8.1.1-2ubuntu0.6+esm6 In general, a standard system update will make all the necessary changes. References:   https://ubuntu.com/security/notices/USN-6473-2   https://ubuntu.com/security/notices/USN-6473-1   CVE-2018-25091, CVE-2023-43804, CVE-2023-45803 Package Information: https://launchpad.net/ubuntu/+source/python-pip/23.2+dfsg... https://launchpad.net/ubuntu/+source/python-pip/23.0.1+df... https://launchpad.net/ubuntu/+source/python-pip/22.0.2+df... https://launchpad.net/ubuntu/+source/python-pip/20.0.2-5u...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds