USN-4601-1: pip vulnerability
22 October 2020
pip could be made to overwrite files as the administrator.
Releases
Packages
- python-pip - Python package installer
Details
It was discovered that pip did not properly sanitize the filename during
pip install. A remote attacker could possible use this issue to read and
write arbitrary files on the host filesystem as root, resulting in a
directory traversal attack. (CVE-2019-20916)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
In general, a standard system update will make all the necessary changes.