Python could be made to run programs if it received specially crafted
socket connections.
Software Description:
- python3.10: An interactive high-level object-oriented language
Details:
Devin Jeanpierre discovered that Python incorrectly handled sockets when
the multiprocessing module was being used. A local attacker could possibly
use this issue to execute arbitrary code and escalate privileges.
The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3.10 3.10.7-1ubuntu0.1 python3.10-minimal 3.10.7-1ubuntu0.1 Ubuntu 22.04 LTS: python3.10 3.10.6-1~22.04.1 python3.10-minimal 3.10.6-1~22.04.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-5713-1
CVE-2022-42919
Get the latest Linux and open source security news straight to your inbox.