|
|
Subscribe / Log in / New account

Ubuntu alert USN-6928-1 (python3.10, python3.8)

From:  Marc Deslauriers <marc.deslauriers@canonical.com>
To:  "ubuntu-security-announce@lists.ubuntu.com" <ubuntu-security-announce@lists.ubuntu.com>
Subject:  [USN-6928-1] Python vulnerabilities
Date:  Tue, 30 Jul 2024 12:33:47 -0400
Message-ID:  <e7c54eda-0744-49f0-af7c-e15aeb4ada23@canonical.com>

========================================================================== Ubuntu Security Notice USN-6928-1 July 30, 2024 python3.10, python3.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python3.10: An interactive high-level object-oriented language - python3.8: An interactive high-level object-oriented language Details: It was discovered that the Python ssl module contained a memory race condition when handling the APIs to obtain the CA certificates and certificate store statistics. This could possibly result in applications obtaining wrong results, leading to various SSL issues. (CVE-2024-0397) It was discovered that the Python ipaddress module contained incorrect information about which IP address ranges were considered "private" or "globally reachable". This could possibly result in applications applying incorrect security policies. (CVE-2024-4032) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3.10 3.10.12-1~22.04.5 python3.10-minimal 3.10.12-1~22.04.5 Ubuntu 20.04 LTS python3.8 3.8.10-0ubuntu1~20.04.11 python3.8-minimal 3.8.10-0ubuntu1~20.04.11 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6928-1 CVE-2024-0397, CVE-2024-4032 Package Information: https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1... https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ub...


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmapFewACgkQZWnYVadE vpPi9BAAuKqXMgqok+MqVbSmikX2McuaOADYx/8NFTHZXfoMrj3dNarqNGbAo9e5 x0OK5g7oMIQY39fojrGNEnq0PlmW9z8aldc9/ijOE9DATHjapaYuvqEorUgqvNzh FENskxyJuAQIWyN00fuv94YGqK+LF7yyIBHio7nXG96daybhPD84NdDouOMcxkAr NpP3O/jy7aaW7ADa0T7dLd70r77SlJrrM4D2tHh91UTt0Q6265WKPxf/Cu92QO0k xOu/K/vg84cOsj46vnyp1mNQ+s25mRCqG89O8a4vAcTwi5BVUJ3hvm5gKEk6tDFj D8gBQGYx2/mlsz9F0y0Hg9o7ymL4UldMrCtbNJm2W2CbIXPRBFsMpnfc0mvbvu6K WZNvCKM6ttBun+y2MZekDA2HzNZ2tnpUUhsUMheY5YAq9FyUz4u4hgbGQ1zCdUv7 +gH5Is8+p8xDoy0C4MaObuMvwG2JxW7aBI3tJ4R/j5d68Zsx52qzjCNJW/cTZpMZ 0f4jksfiU4I2tO0Me62XnUWLYhWXlJmj/pa2PZJEnVL7CcT+szxP7nW8utrdBCeU EcHsG6s6EGh8n6OwN9FTvaC4UTkOCRClSc+v7HGqddBAgDL7lDNflhSmMs35Em9p IzBmkBhjJuTyL9DEzmTKo/2wkFxa5jMM5J0sBXgI90GW8NNBjWU= =0bZF -----END PGP SIGNATURE-----


Attachment: None (type=text/plain)


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds