drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in virtualenv
| Name: |
Ausführen beliebiger Kommandos in virtualenv |
|
| ID: |
USN-7271-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS |
|
| Datum: |
Di, 18. Februar 2025, 18:21 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-53899 |
|
| Applikationen: |
virtualenv |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============8477491553567444756== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------Cgs2XO8HBzZnh9waqY6dYQix"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------Cgs2XO8HBzZnh9waqY6dYQix Content-Type: multipart/mixed; boundary="------------4rgk7QC9xtkIYK80MXXxJImK"; protected-headers="v1" From: Octavio Galland <octavio.galland@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <99239cfe-68ee-43da-b270-aa3f72223d64@canonical.com> Subject: [USN-7271-1] virtualenv vulnerability
--------------4rgk7QC9xtkIYK80MXXxJImK Content-Type: multipart/mixed; boundary="------------APs2SNEViI6lxLsj166pro6j"
--------------APs2SNEViI6lxLsj166pro6j Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7271-1 February 18, 2025
python-virtualenv vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS - Ubuntu 20.04 LTS
Summary:
python-virtualenv could be made to crash or run programs as your login if it opened a specially crafted file.
Software Description: - python-virtualenv: Python virtual environment creator
Details:
It was discovered that virtualenv incorrectly handled paths when activating virtual environments. An attacker could possibly use this issue to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04 LTS python3-virtualenv 20.13.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro virtualenv 20.13.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro
Ubuntu 20.04 LTS python3-virtualenv 20.0.17-1ubuntu0.4+esm1 Available with Ubuntu Pro virtualenv 20.0.17-1ubuntu0.4+esm1 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7271-1 CVE-2024-53899
--------------APs2SNEViI6lxLsj166pro6j Content-Type: application/pgp-keys; name="OpenPGP_0xF6E140F6DB359E58.asc" Content-Disposition: attachment; filename="OpenPGP_0xF6E140F6DB359E58.asc" Content-Description: OpenPGP public key Content-Transfer-Encoding: quoted-printable
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBGZU5HkBEAC5gtbx2yg8wn9n1x0UKtCSpHCzCL/DDMi+ez8DqaDy2ym8waOh X6ZeMYxEcRlZMEieo3VfpdioYr/reAs0XViMlSeM7DiMFN1Q6E3yDAaW8Ne/6OwU 6ID8AVV12dooWoa6Xa4hbLLLBMH0XRd8DVw4Zn6s+C18AMweC7Uf3ib62WI7jAxZ vaRLV+1WWRBQlse5Of7hpvYsqbGuA4l/hzM2LYmWXXDOAsG2DhbSioQdSd89clH9 o1A/fCWNcVC80b7haAG96OaqXSaMny25Vdz5cGWj9SNOcVoXSoGdlu4JFQ/RQo/U VRk2XTAKVJdIsVW5Fp/4O3z7nLzygDlC10YM0JAfNCuAgcr8pp14Tlz8ExMNqO7z yhQt0iCn63UD5f/UB0oK2Ix8I5QK4JoHOeOUq8sDZez+bfX+D2KrYLQ4HONWNR2T 7XVnK9YNfWZyztZ7kVZlG3r/WSn1D6ZBj+Aolv2XtzweAn8HNxR3yZZe+1FoHLV3 JnNG1zaQs+WQJFGcQdjzdu5nvKXf4o0TJuakMbhcAh9DmhHGhRvesp9LOrDKxv7C OXm8ER6G1wRyIh78bPTe6zRfMP49MX1LKUOHf+2T4IRt/7bz4OFXl5vfCWlAOUWN i6EJ2qImw+2ouEKu9X/9p+I3FDALtOoys1MBKAdQsG/RhDfB2Bt/BRtZ7wARAQAB zTZPY3RhdmlvIEFkb2xmbyBHYWxsYW5kIDxvY3RhdmlvLmdhbGxhbmRAY2Fub25p Y2FsLmNvbT7CwZEEEwEKADsWIQRH8irnonVCkXIr8JD24UD22zWeWAUCZlTkeQIb AwULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRD24UD22zWeWNDaEACJOesZ 823ro/m2o9PVvjyw0wKn1/beHamwJFpp1ciDwYTLemsGjJf1e5D2HBVNTGSqmmnh IZVSeCq6Ni9PbJlGsxJrGlVpaJRS8LBD/3xQNg5KYyT5loSge53oFBZgTAIj2sNX UmtWZagQlBPdOB982CHqO6+2J/Dbly6qSKp8UUgatUNzbvClVhJmxA9TpV2WumSA e4zR1JirXZGGgCg5NLhFiGtySnyS4lcl+hjtdYsvD3FDOiAJaSMJfCagW1gmpjX2 znaDhexnT6rXvWeV8ZP5xbMJfS7UxeArdW09uBBohjFteHzaBnqppVxMOwMaId0w /+TRFsT+sDPMsdMBakJ3Tw6WS4qbfY8pbJGuvKZ4x5ZJlZdXpx9wsVY7EsA2qRqb GtEFsyy+7zQ4HUTTbSmUc9PATpmcyJpXGM47iaGmN735Qc2gcZZLHYfylEs8bxHo DeDxnDSDZhw+0E2/ZRRLUOlUzsxxGWW5tsJ+GHe69eceiDQJOdAiomJkSJMXQStv vfsDd5wmX8Z8Yf+NGwWK0X/KQXBo6a9/6aDRE9HwyadYF+3F87dbr8KY/GlhYn6i s5YRgGEIynvOVvxfrb3EAXe0f6iJq1TCEyvKAn3zhaw070wZWsVploAPJ8y9PKwi UaHfH6s9RVZ94Qtz4BwasdGo2mnHJP0NWQcsnc7BTQRmVOR5ARAAuVJlTQ0Me3Fo N8cVaUnux5nFraEUdLdKM9iD8L5Pj+LCJGHWkb3yGfdcWHkV9eOKTuixSajdJEj7 EKdzYaLRyKItwT0PFPcgNV7C6OGZYGvOd+9jGxMH4P9ENf+3eNurt+Za8SPLboRZ faprZhn2nIX8JWPqWDzV3YUkq4Oyxo7DJJenuDQLPnG3WtcKogOpIpbw2h0vm04E O5honjtDY8iwyYabl17/bFmZowL2SOmAgohWsGgzC3+/Zoyr7n80Ayv1nl/6Tecg hqrRNfWTG8Y2e25p90DSv6D+NUwLWTaFHP1OivVfnvTTyrtQUGrV2rRR5AYzmqaz NjGlAZ0FzZdKVV1vjgFZNnHH2avyQUALz3miaB3h2GHJbhI9EjhOkv+jVzMR8Pok w19kS0ewed+O8PG5CecJZfwgDNWaqLL3QGYMFVKC5n8Ekv+XfqNxcgT3un8Zles5 V3ejOhdjvQqvKuV4ey5nZ8he/kzZbW27oGiy58SxK9RMy57bs3ugm8wbKc1B/EOX 2LdLo1kdQqCa3lWDReyb0S2I14ml9qddc3UA/IBtZDy0AfOlNbwzV+V9SW8j8lXh 4KGGNfNfsuRsSoiYNyIzCQEtRCEm9c/SkTwhW2oNTdztRtageji91y9zOPRf3lN9 HpDR05a8AoC1YonHZxxNcxQMScIUHp8AEQEAAcLBdgQYAQoAIBYhBEfyKueidUKR civwkPbhQPbbNZ5YBQJmVOR5AhsMAAoJEPbhQPbbNZ5Yef0P/AwNuhnujouSKmc/ Nov/pHkcujZaYsn1iIoYEqhmWjpnBQav+m63G+RZ5zjqu36G7uhZkpYILPihLOJZ X2SuTIrVitnJ+ocXK2QFLbW8gUlvqRi4kP5XbUQ0yAVWzPFlY9BNK6DUrj0LeC5n 4i+llAI9d50MiqlUDp+pdCotsuyE0PuuGDkY943LXWnPRPnHCv96ocOglN/dyVCB N1fjEStCG4q3xzYO1KX3WnPOdurPh/CDw6Uypfr6VOlU+3BN+7t2wCk2V7tDjaYH 8/pZCzHCH3FDzUdEuVRBE0eB73yNFv1/SgVstqvTUfcYnaOm2EgvtBB14gIC8qBO GPSjlh/7kMmD7m8ZiJNknUOL04mOFkDufnbcNUxmYEbn33TCbSIWDjt3RxTHVnzB UZjYdBkUNJU1JcxDRJzoILSMUSLSH69z90UaArMiKMGtRoIQj2vSSQzdUgeGBBKv vqE74KMQ0kj/qLaX6cCLUBX2kBShMVbQ7igp3Jytqj8hRvpPVo+xoXd42UWmLTCa ISvwLtKvzrXYT80yYVUHhCx9keJ+zuOloshIPmvdVvfuoVaGVMpf6/gOJniRuUwA ufUEKoy7Nl7w6e9pNIM7S5k7TqinqALWixkER9AfIOmEYYsmTVTBDLjsSEv0QWyJ QGrNPtvSWtSzFkAmdaSP92Yi2kr2 =3DZpuF -----END PGP PUBLIC KEY BLOCK-----
--------------APs2SNEViI6lxLsj166pro6j--
--------------4rgk7QC9xtkIYK80MXXxJImK--
--------------Cgs2XO8HBzZnh9waqY6dYQix Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAme0qQQFAwAAAAAACgkQ9uFA9ts1nliQ /xAAjZ9zqfnSnNeml12zy308XBE4Crx2GpAVWI6McTbbjUaoEU0SMC5Ol1UDk2P+qqvQh6Gz0JN4 3XmAK1SM8Kfg+AI1xp4IMiZdg8ktEo8Fb2K7k7jMlzbo+UmTi0io2hSvHwhiNTHfaefuGP9SxOcf wFHfc90tsDSxJZY4Vvotar/is1k8UE+TZVRDe0MmDZbvyRU9hIhK1Lo/mt/LlfnJlzUNeDDsCHSK G7IvPY1MPdIAKkqb7Fqw+Km2+Nb6Ps5qc2AVOpmD8sGZMPH/awC7UA8hrXqUY/fNtTc6wY6ktJsr jFVXV1e/AdZ7pl5HpbLt4/5Nu4K1dpS2fwOLKWIjejQl59qBxJanXIfXgruqG2a+Gud4H9XtFr5n IoW4ELsKgXTl6YHPrrnBnrdEmeMz0+Ptqh3boIoYGKBWdarRtTplGIP/Ah3UghUH73DjP6ElS68b 3YRBbZZALX7gQETJHWEDDxlIfMwXOTs2qzY6NTMC594RUYzy5iEcnh1HRB6FfwyOElFdBcCFaddT FWTFmOl/w07JeDeJr2vkYF7c4jDi9TjSveYKkXI7RdqA8TGqApu64D35J/Y6J1XV2W3VHEZ4+3Vm kYvrZDdng/ktfzIJ0N9rFg+MhIpyvH3tIi7bkj5kOVMxdAZ9EZMSIFZCuE5hqW5b05dlTF1VqTSN jd4= =zeka -----END PGP SIGNATURE-----
--------------Cgs2XO8HBzZnh9waqY6dYQix--
--===============8477491553567444756== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============8477491553567444756==--
|
|
|
|