Login
Newsletter
Werbung

Sicherheit: Mangelnde Eingabeprüfung in pip
Aktuelle Meldungen Distributionen
Name: Mangelnde Eingabeprüfung in pip
ID: USN-4961-1
Distribution: Ubuntu
Plattformen: Ubuntu 20.04 LTS
Datum: Mi, 19. Mai 2021, 23:30
Referenzen: Keine Angabe
Applikationen: pip

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8909187120661473334==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="UprH8xxoPtZlw4BMdSiWkqIYvTy4VHfP0"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--UprH8xxoPtZlw4BMdSiWkqIYvTy4VHfP0
Content-Type: multipart/mixed;
boundary="H3loG1niWcx8e3Xke0qSsBgPKgpGqf48A";
protected-headers="v1"
From: Marc Deslauriers <marc.deslauriers@canonical.com>
Reply-To: Ubuntu Security <security@ubuntu.com>
To: "ubuntu-security-announce@lists.ubuntu.com"
<ubuntu-security-announce@lists.ubuntu.com>
Message-ID: <0de292d9-5061-f1d3-6cc9-c731832d653c@canonical.com>
Subject: [USN-4961-1] pip vulnerability

--H3loG1niWcx8e3Xke0qSsBgPKgpGqf48A
Content-Type: text/plain; charset=utf-8
Content-Language: en-C
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-4961-1
May 19, 2021

python-pip vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

pip could be made to install different git revisions.

Software Description:
- python-pip: Python package installer

Details:

It was discovered that pip incorrectly handled unicode separators in git
references. A remote attacker could possibly use this issue to install a
different revision on a repository.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
python3-pip 20.0.2-5ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4961-1
https://launchpad.net/bugs/1926957

Package Information:
https://launchpad.net/ubuntu/+source/python-pip/20.0.2-5ubuntu1.5


--H3loG1niWcx8e3Xke0qSsBgPKgpGqf48A--

--UprH8xxoPtZlw4BMdSiWkqIYvTy4VHfP0
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmCk9ZYACgkQZWnYVadE
vpM4Qw/9E3DJ/TBEcxtpk0g0oO0LpDMvCeWf71BIGQVlIQFdjlK2JlrL5v0oeDGK
RbYZN5Xh01rG4simtTVMuGkUoaHTywS2Y/DwVOcDLuRRLf6Dv41fNYGENZq8PnQc
AK0qvpX676QoiQODyl08C3SxHuqKQpWqNYvkSuaOIJo2aLkiUJ7sxNb2r8dYxtVJ
Aa4/bNAF5LZl0+5F66n6YuQSs/iVsajEoPn0wDLdYEVwv54+sQlrNSHN/pcAwK3Z
JMsudDpxmY76DqUQFK+jNGcqpCFJ91YuE7+PKLnCgQhQ1teHyFsvr9RNv2LrU9K8
8xC4XtwqsK/oE1rbKQMJCc8PAc2GHsrFmLJrm3C3eXk6UIvJ6TzOs65Qn3Cs08k8
dKa3Dnn/DEWqcKNE4yNeD3VnpPtvwJbuOVEAdvvLvIj20+dbCuo0yFrSfJzw+eZB
Zg52rJqjToLQBxW0JTcosDxYs0yGpn8ZT2T8ypRHcHzzAx1wqjFO3fVTNx3Tla4J
FPnEm9xnLOM80lIO1GTAdD73qToYjKwudbbVSPva8t0s3ji+r8LgOd827x7UpiNr
SnazV4xXo0ZvOWs9kc4mIzN/GI6O7lM41iCGxX5tL+WdU8k7g/F+PYWMG1aQrV8a
zX4dEV/SGVH/jqfDFqPyXeN4ql7EYTqcmUA0LilroaE2Ba96zJc=
=f3VD
-----END PGP SIGNATURE-----

--UprH8xxoPtZlw4BMdSiWkqIYvTy4VHfP0--


--===============8909187120661473334==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============8909187120661473334==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung