Packages
- python2.7 - An interactive high-level object-oriented language
- python3.10 - An interactive high-level object-oriented language
- python3.6 - An interactive high-level object-oriented language
- python3.8 - An interactive high-level object-oriented language
Details
Nicky Mouha discovered that Python incorrectly handled certain SHA-3 internals.
An attacker could possibly use this issue to cause a crash or execute arbitrary code.
(CVE-2022-37454)
It was discovered that Python incorrectly handled certain IDNA inputs.
An attacker could possibly use this issue to expose sensitive information
denial of service, or cause a crash.
(CVE-2022-45061)
Nicky Mouha discovered that Python incorrectly handled certain SHA-3 internals.
An attacker could possibly use this issue to cause a crash or execute arbitrary code.
(CVE-2022-37454)
It was discovered that Python incorrectly handled certain IDNA inputs.
An attacker could possibly use this issue to expose sensitive information
denial of service, or cause a crash.
(CVE-2022-45061)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
22.10 kinetic | python3.10 – 3.10.7-1ubuntu0.2 | ||
libpython3.10 – 3.10.7-1ubuntu0.2 | |||
22.04 jammy | python3.10 – 3.10.6-1~22.04.2 | ||
libpython3.10 – 3.10.6-1~22.04.2 | |||
20.04 focal | libpython3.8 – 3.8.10-0ubuntu1~20.04.6 | ||
python3.8 – 3.8.10-0ubuntu1~20.04.6 | |||
18.04 bionic | libpython2.7 – 2.7.17-1~18.04ubuntu1.10 | ||
python2.7 – 2.7.17-1~18.04ubuntu1.10 | |||
python3.6 – 3.6.9-1~18.04ubuntu1.9 | |||
libpython3.6 – 3.6.9-1~18.04ubuntu1.9 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.