USN-5713-1: Python vulnerability
3 November 2022
Python could be made to run programs if it received specially crafted socket connections.
Releases
Packages
- python3.10 - An interactive high-level object-oriented language
Details
Devin Jeanpierre discovered that Python incorrectly handled sockets when
the multiprocessing module was being used. A local attacker could possibly
use this issue to execute arbitrary code and escalate privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.10
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.