drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in virtualenv (Aktualisierung)
| Name: |
Ausführen beliebiger Kommandos in virtualenv (Aktualisierung) |
|
| ID: |
USN-7271-2 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 24.04 LTS |
|
| Datum: |
Di, 25. Februar 2025, 23:03 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-53899 |
|
| Applikationen: |
virtualenv |
|
| Update von: |
Ausführen beliebiger Kommandos in virtualenv |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============7540890517193519194== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------fJ7HDNjux0DC1Up4NquTasvz"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------fJ7HDNjux0DC1Up4NquTasvz Content-Type: multipart/mixed; boundary="------------RrY60PlqHmBuTzlibpuvkTQw"; protected-headers="v1" From: Octavio Galland <octavio.galland@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <c61d6164-9e7b-4f5a-ae2b-62fbc7c71cc1@canonical.com> Subject: [USN-7271-2] virtualenv vulnerability
--------------RrY60PlqHmBuTzlibpuvkTQw Content-Type: multipart/mixed; boundary="------------RQ8CnfFnyDom0Ta34vlDBWlQ"
--------------RQ8CnfFnyDom0Ta34vlDBWlQ Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7271-2 February 25, 2025
python-virtualenv vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
Summary:
virtualenv could be made to crash or run programs as your login if it opened a specially crafted file.
Software Description: - python-virtualenv: tool to create isolated Python environments
Details:
USN-7271-1 fixed a vulnerability in virtualenv. This update provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that virtualenv incorrectly handled paths when activating virtual environments. An attacker could possibly use this issue to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04 LTS python3-virtualenv 20.25.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro virtualenv 20.25.0+ds-2ubuntu0.1~esm1 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7271-2 https://ubuntu.com/security/notices/USN-7271-1 CVE-2024-53899
--------------RQ8CnfFnyDom0Ta34vlDBWlQ Content-Type: application/pgp-keys; name="OpenPGP_0xF6E140F6DB359E58.asc" Content-Disposition: attachment; filename="OpenPGP_0xF6E140F6DB359E58.asc" Content-Description: OpenPGP public key Content-Transfer-Encoding: quoted-printable
-----BEGIN PGP PUBLIC KEY BLOCK-----
xsFNBGZU5HkBEAC5gtbx2yg8wn9n1x0UKtCSpHCzCL/DDMi+ez8DqaDy2ym8waOh X6ZeMYxEcRlZMEieo3VfpdioYr/reAs0XViMlSeM7DiMFN1Q6E3yDAaW8Ne/6OwU 6ID8AVV12dooWoa6Xa4hbLLLBMH0XRd8DVw4Zn6s+C18AMweC7Uf3ib62WI7jAxZ vaRLV+1WWRBQlse5Of7hpvYsqbGuA4l/hzM2LYmWXXDOAsG2DhbSioQdSd89clH9 o1A/fCWNcVC80b7haAG96OaqXSaMny25Vdz5cGWj9SNOcVoXSoGdlu4JFQ/RQo/U VRk2XTAKVJdIsVW5Fp/4O3z7nLzygDlC10YM0JAfNCuAgcr8pp14Tlz8ExMNqO7z yhQt0iCn63UD5f/UB0oK2Ix8I5QK4JoHOeOUq8sDZez+bfX+D2KrYLQ4HONWNR2T 7XVnK9YNfWZyztZ7kVZlG3r/WSn1D6ZBj+Aolv2XtzweAn8HNxR3yZZe+1FoHLV3 JnNG1zaQs+WQJFGcQdjzdu5nvKXf4o0TJuakMbhcAh9DmhHGhRvesp9LOrDKxv7C OXm8ER6G1wRyIh78bPTe6zRfMP49MX1LKUOHf+2T4IRt/7bz4OFXl5vfCWlAOUWN i6EJ2qImw+2ouEKu9X/9p+I3FDALtOoys1MBKAdQsG/RhDfB2Bt/BRtZ7wARAQAB zTZPY3RhdmlvIEFkb2xmbyBHYWxsYW5kIDxvY3RhdmlvLmdhbGxhbmRAY2Fub25p Y2FsLmNvbT7CwZEEEwEKADsWIQRH8irnonVCkXIr8JD24UD22zWeWAUCZlTkeQIb AwULCQgHAgIiAgYVCgkICwIEFgIDAQIeBwIXgAAKCRD24UD22zWeWNDaEACJOesZ 823ro/m2o9PVvjyw0wKn1/beHamwJFpp1ciDwYTLemsGjJf1e5D2HBVNTGSqmmnh IZVSeCq6Ni9PbJlGsxJrGlVpaJRS8LBD/3xQNg5KYyT5loSge53oFBZgTAIj2sNX UmtWZagQlBPdOB982CHqO6+2J/Dbly6qSKp8UUgatUNzbvClVhJmxA9TpV2WumSA e4zR1JirXZGGgCg5NLhFiGtySnyS4lcl+hjtdYsvD3FDOiAJaSMJfCagW1gmpjX2 znaDhexnT6rXvWeV8ZP5xbMJfS7UxeArdW09uBBohjFteHzaBnqppVxMOwMaId0w /+TRFsT+sDPMsdMBakJ3Tw6WS4qbfY8pbJGuvKZ4x5ZJlZdXpx9wsVY7EsA2qRqb GtEFsyy+7zQ4HUTTbSmUc9PATpmcyJpXGM47iaGmN735Qc2gcZZLHYfylEs8bxHo DeDxnDSDZhw+0E2/ZRRLUOlUzsxxGWW5tsJ+GHe69eceiDQJOdAiomJkSJMXQStv vfsDd5wmX8Z8Yf+NGwWK0X/KQXBo6a9/6aDRE9HwyadYF+3F87dbr8KY/GlhYn6i s5YRgGEIynvOVvxfrb3EAXe0f6iJq1TCEyvKAn3zhaw070wZWsVploAPJ8y9PKwi UaHfH6s9RVZ94Qtz4BwasdGo2mnHJP0NWQcsnc7BTQRmVOR5ARAAuVJlTQ0Me3Fo N8cVaUnux5nFraEUdLdKM9iD8L5Pj+LCJGHWkb3yGfdcWHkV9eOKTuixSajdJEj7 EKdzYaLRyKItwT0PFPcgNV7C6OGZYGvOd+9jGxMH4P9ENf+3eNurt+Za8SPLboRZ faprZhn2nIX8JWPqWDzV3YUkq4Oyxo7DJJenuDQLPnG3WtcKogOpIpbw2h0vm04E O5honjtDY8iwyYabl17/bFmZowL2SOmAgohWsGgzC3+/Zoyr7n80Ayv1nl/6Tecg hqrRNfWTG8Y2e25p90DSv6D+NUwLWTaFHP1OivVfnvTTyrtQUGrV2rRR5AYzmqaz NjGlAZ0FzZdKVV1vjgFZNnHH2avyQUALz3miaB3h2GHJbhI9EjhOkv+jVzMR8Pok w19kS0ewed+O8PG5CecJZfwgDNWaqLL3QGYMFVKC5n8Ekv+XfqNxcgT3un8Zles5 V3ejOhdjvQqvKuV4ey5nZ8he/kzZbW27oGiy58SxK9RMy57bs3ugm8wbKc1B/EOX 2LdLo1kdQqCa3lWDReyb0S2I14ml9qddc3UA/IBtZDy0AfOlNbwzV+V9SW8j8lXh 4KGGNfNfsuRsSoiYNyIzCQEtRCEm9c/SkTwhW2oNTdztRtageji91y9zOPRf3lN9 HpDR05a8AoC1YonHZxxNcxQMScIUHp8AEQEAAcLBdgQYAQoAIBYhBEfyKueidUKR civwkPbhQPbbNZ5YBQJmVOR5AhsMAAoJEPbhQPbbNZ5Yef0P/AwNuhnujouSKmc/ Nov/pHkcujZaYsn1iIoYEqhmWjpnBQav+m63G+RZ5zjqu36G7uhZkpYILPihLOJZ X2SuTIrVitnJ+ocXK2QFLbW8gUlvqRi4kP5XbUQ0yAVWzPFlY9BNK6DUrj0LeC5n 4i+llAI9d50MiqlUDp+pdCotsuyE0PuuGDkY943LXWnPRPnHCv96ocOglN/dyVCB N1fjEStCG4q3xzYO1KX3WnPOdurPh/CDw6Uypfr6VOlU+3BN+7t2wCk2V7tDjaYH 8/pZCzHCH3FDzUdEuVRBE0eB73yNFv1/SgVstqvTUfcYnaOm2EgvtBB14gIC8qBO GPSjlh/7kMmD7m8ZiJNknUOL04mOFkDufnbcNUxmYEbn33TCbSIWDjt3RxTHVnzB UZjYdBkUNJU1JcxDRJzoILSMUSLSH69z90UaArMiKMGtRoIQj2vSSQzdUgeGBBKv vqE74KMQ0kj/qLaX6cCLUBX2kBShMVbQ7igp3Jytqj8hRvpPVo+xoXd42UWmLTCa ISvwLtKvzrXYT80yYVUHhCx9keJ+zuOloshIPmvdVvfuoVaGVMpf6/gOJniRuUwA ufUEKoy7Nl7w6e9pNIM7S5k7TqinqALWixkER9AfIOmEYYsmTVTBDLjsSEv0QWyJ QGrNPtvSWtSzFkAmdaSP92Yi2kr2 =3DZpuF -----END PGP PUBLIC KEY BLOCK-----
--------------RQ8CnfFnyDom0Ta34vlDBWlQ--
--------------RrY60PlqHmBuTzlibpuvkTQw--
--------------fJ7HDNjux0DC1Up4NquTasvz Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsF5BAABCAAjFiEER/Iq56J1QpFyK/CQ9uFA9ts1nlgFAme98DsFAwAAAAAACgkQ9uFA9ts1nliB xxAAsYHttnNiR0rp753B3LaUtJmIy1CNotsz5flm+7ind3NKzMdml2IAJOShz9xkvEg+eYQW9rLy uKDvSXdJm1AJwkgHthq9LRGiaOXiSuS3s281Ao5e1r45HpZeP1cL/e/F+n6H35ccp+eAAvY83lqG AMGK/z34VkK9LfaVamGaSs2tFyZrSFARV/q2awSin6BPJ1HVUNd/CGYpyZKh2oHWfeLuh4smA+XK AQm8GgqoOD+LPRtQbbOId+run3XMV0Tste+m0tElxhMfBy0b6wA+jYGEJjVWFHoCe2qHpCEx12ik KIZLrninl5ampTSlOWZp0eBvB1d94rrVkdRe4e4ILZgaHHuBK50mPVCJ8PVdH3b7zqqbCKWTZsdG jLB+Nuahut/CvLMnPKMUhQ4c0/WwFBOvLCHtXmqaNgdLFBpRtP1LaL1cthynhg9MWDZQANBI1dNV BB5NH4X3ZAHUp9vP/c3abHKNbjMwlAefAgvoespSDAAdFJ+zy79pE+vyPPpbLXhGIe5dkynIpZXn 8UDw9yo5CMAG7a4hAa+WzB3wMyVE44u62Nh3nAMitA5Qd9Q9tR241QKtjaeVlAZyoT4YKJT7lQkS CDYj+ky+JxfKRMSZ0dDjWkbIQidFmleKcPUDoEu5I+/wyTLRj56d76jrvzTRT/wD25AIMxRGz4EM 7lU= =nGB8 -----END PGP SIGNATURE-----
--------------fJ7HDNjux0DC1Up4NquTasvz--
--===============7540890517193519194== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============7540890517193519194==--
|
|
|
|