USN-4655-1: Werkzeug vulnerabilities

01 December 2020

Several security issues were fixed in Werkzeug.

Releases

Packages

  • python-werkzeug - collection of utilities for WSGI applications
  • python-werkzeug - collection of utilities for WSGI applications (Python 2.x)

Details

It was discovered that Werkzeug has insufficient debugger PIN randomness.
An attacker could use this issue to access sensitive information. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-14806)

It was discovered that Werkzeug incorrectly handled certain URLs.
An attacker could possibly use this issue to cause pishing attacks.
This issue only affected Ubuntu 16.04 LTS. (CVE-2020-28724)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.04
Ubuntu 16.04

In general, a standard system update will make all the necessary changes.