USN-7015-2
Dashboard / Vulnerabilities / USN-7015-2
USN-7015-2
Summary: python2.7, python3.5 vulnerabilities
Details: USN-7015-1 fixed several vulnerabilities in Python. This update provides one of the corresponding updates for python2.7 for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and a second for python3.5 for Ubuntu 16.04 LTS. Original advisory details: It was discovered that Python allowed excessive backtracking while parsing certain tarfile headers. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. This issue only affected python3.5 for Ubuntu 16.04 LTS (CVE-2024-6232) It was discovered that the Python http.cookies module incorrectly handled parsing cookies that contained backslashes for quoted characters. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-7592)
References: https://ubuntu.com/security/notices/USN-7015-2, https://ubuntu.com/security/CVE-2024-6232, https://ubuntu.com/security/CVE-2024-7592
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/python2.7?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
