USN-4961-2: pip vulnerability
19 May 2022
pip could be made to install different git revisions.
Releases
Packages
- python-pip - Python package installer
Details
USN-4961-1 fixed a vulnerability in pip. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 ESM.
Original advisory details:
It was discovered that pip incorrectly handled unicode separators in git
references. A remote attacker could possibly use this issue to install a
different revision on a repository.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
python3-pip
-
9.0.1-2.3~ubuntu1.18.04.5+esm2
Available with Ubuntu Pro
Ubuntu 16.04
-
python3-pip
-
8.1.1-2ubuntu0.6+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
python3-pip
-
1.5.4-1ubuntu4+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.