Ubuntu Security Notice USN-3134-1
22nd November, 2016
python2.7, python3.2, python3.4, python3.5 vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary
Several security issues were fixed in Python.
Software description
- python2.7
- An interactive high-level object-oriented language
- python3.2
- An interactive high-level object-oriented language
- python3.4
- An interactive high-level object-oriented language
- python3.5
- An interactive high-level object-oriented language
Details
It was discovered that the smtplib library in Python did not return an
error when StartTLS fails. A remote attacker could possibly use this to
expose sensitive information. ()
Insu Yun discovered an integer overflow in the zipimporter module in
Python that could lead to a heap-based overflow. An attacker could
use this to craft a special zip file that when read by Python could
possibly execute arbitrary code. ()
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 16.04 LTS:
- Ubuntu 14.04 LTS:
- Ubuntu 12.04 LTS:
To update your system, please follow these instructions:
,
,
CVE-2016-5699
SOCIAL SHARE CARD GENERATOR