UBUNTU-CVE-2021-3572
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3572
UBUNTU-CVE-2021-3572
Summary:
Details: A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
References: https://ubuntu.com/security/CVE-2021-3572, https://github.com/pypa/pip/pull/9827, https://github.com/pypa/pip/issues/10042, https://github.com/pypa/pip/issues/10042#issuecomment-857452480, https://github.com/skazi0/CVE-2021-3572/blob/master/CVE-2021-3572-v9.0.1.patch, https://ubuntu.com/security/notices/USN-4961-2, https://www.cve.org/CVERecord?id=CVE-2021-3572
Affected packages
Package
Name: python-pip
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
