CVE-2011-1521
Publication date 24 May 2011
Last updated 24 July 2024
Ubuntu priority
The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.
Status
Package | Ubuntu Release | Status |
---|---|---|
python2.4 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy |
Fixed 2.4.5-1ubuntu4.4
|
|
6.06 LTS dapper | Ignored end of life | |
python2.5 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty | Not in release | |
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy |
Fixed 2.5.2-2ubuntu6.2
|
|
6.06 LTS dapper | Not in release | |
python2.6 | 12.04 LTS precise | Not in release |
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 2.6.6-6ubuntu7.1
|
|
10.10 maverick | Ignored end of life | |
10.04 LTS lucid |
Fixed 2.6.5-1ubuntu6.1
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
python2.7 | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 2.7.1-5ubuntu2.2
|
|
10.10 maverick | Ignored end of life | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
python3.1 | 12.04 LTS precise | Not in release |
11.10 oneiric | Not in release | |
11.04 natty |
Fixed 3.1.3-1ubuntu1.1
|
|
10.10 maverick |
Fixed 3.1.2+20100915-0ubuntu4.1
|
|
10.04 LTS lucid |
Fixed 3.1.2-0ubuntu3.1
|
|
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
python3.2 | 12.04 LTS precise |
Not affected
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Fixed 3.2-1ubuntu1.1
|
|
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release |
Notes
Patch details
Package | Patch details |
---|---|
python2.4 | |
python2.5 | |
python2.6 | |
python2.7 | |
python3.1 | |
python3.2 |
References
Related Ubuntu Security Notices (USN)
- USN-1613-1
- Python 2.5 vulnerabilities
- 17 October 2012
- USN-1314-1
- Python 3 vulnerabilities
- 19 December 2011
- USN-1592-1
- Python 2.7 vulnerabilities
- 2 October 2012
- USN-1613-2
- Python 2.4 vulnerabilities
- 17 October 2012
- USN-1596-1
- Python 2.6 vulnerabilities
- 4 October 2012