Description: | Summary: The remote host is missing an update for the 'python3.9' package(s) announced via the USN-5888-1 advisory.
Vulnerability Insight: It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2015-20107)
Hamza Avvan discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2021-28861)
It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2022-37454, CVE-2022-42919)
It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-45061, CVE-2023-24329)
Affected Software/OS: 'python3.9' package(s) on Ubuntu 20.04.
Solution: Please install the updated package(s).
CVSS Score: 8.0
CVSS Vector: AV:N/AC:L/Au:S/C:P/I:C/A:P
|