Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.announce.security > #3603 > unrolled thread

[SECURITY] [DSA 5065-1] ipython security update

Started byMoritz Muehlenhoff <jmm@debian.org>
First post2022-01-31 21:00 +0100
Last post2022-01-31 21:00 +0100
Articles 1 — 1 participant

Back to article view | Back to linux.debian.announce.security


Contents

  [SECURITY] [DSA 5065-1] ipython security update Moritz Muehlenhoff <jmm@debian.org> - 2022-01-31 21:00 +0100

#3603 — [SECURITY] [DSA 5065-1] ipython security update

FromMoritz Muehlenhoff <jmm@debian.org>
Date2022-01-31 21:00 +0100
Subject[SECURITY] [DSA 5065-1] ipython security update
Message-ID<DLL0d-7Wg-9@gated-at.bofh.it>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5065-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
January 31, 2022                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : ipython
CVE ID         : CVE-2022-21699

It was discovered that IPython, an enhanced interactive Python shell,
executed config files from the current working directory, which could
result in cross-user attacks if run from a directory multiple users
may write to.

For the oldstable distribution (buster), this problem has been fixed
in version 5.8.0-1+deb10u1.

For the stable distribution (bullseye), this problem has been fixed in
version 7.20.0-1+deb11u1.

We recommend that you upgrade your ipython packages.

For the detailed security status of ipython please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ipython

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmH4PYgACgkQEMKTtsN8
TjY8vw//d1FA/8Q7ysEl6ztpU7bDmJ+xQ3zKKL/N7usjY4WxDSxzdiSfSdzQNSLC
DZEUezNCB4Y7ojBuH4I1bvf7aHTTetGTBqgdqlZ9hEdTxSrkkz2u1HyzkyxUlhfj
Zt+SnSX2xckcRHv1jV0bv45h1Mv1WPNm6yeixVVTZ3KBYMwzax44yWKji4iPa9r2
uEECeStNONAC+h4bs10FQBN5FvcNlj047ocUkuZUzCKp6eEhOlpDYCY45Hhf2HNI
IQ3Kh5a2vulXugUGo9zduxvnkJmSMzITc4Y8aIXnbZKqGl04Xg4FoAt4oe5+Z3tS
Ug+BvIAlDHzuevI4ghnLe/QJ+uDYcmmEB1dotiCb1BQrGAZ8XDGFkh3nR+Vxw4OO
l4BgjMAY14MrpWrcViwUEiAY3f3OuYnDoCPmWDuNyC1z5d33NIVEBmbqk/6jmaNR
wNAHLktw5LA4v9LlpAUae0qBu6N0rl+CJVgazZGMTfXmnWDy2YZRtBtD1jd6FjDw
3+uAl4XldXxOAGJONBT/izdY2te1xPupTKCDZK4jdAvvp+SoP+cG8m1BHv3x6rGF
/kQJJZl4Tqd+83WTPBV4mHiSqs4Wb+yOPKWJLaIhOkcnLANq4MDMua/IVgBC+x/V
y6sd+3jJ93K/E6Qs2lhwThpt0CfylG1xnST43KZYBPe2lk4gf9Y=
=gyVd
-----END PGP SIGNATURE-----

[toc] | [standalone]


Back to top | Article view | linux.debian.announce.security


csiph-web