USN-4378-1: Flask vulnerability
1 June 2020
Flask could be made to consume a large amount of memory if it received a specially crafted input.
Releases
Packages
- flask - Micro web framework based on Werkzeug and Jinja2
Details
It was discovered that Flask incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
Ubuntu 16.04
Ubuntu 14.04
-
python-flask
-
0.10.1-2ubuntu0.1~esm1
Available with Ubuntu Pro
-
python3-flask
-
0.10.1-2ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.