Hi everyone! Hope you're all having a nice life!
I just found this while I was checking this site which I use to visit regularly and was wondering whether if this Ubuntu Alert USN-3463-1 Werkzeug vulnerability is something we should worry about and if so, has it been taken care of already?.
The security bulletin says:
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
It was discovered that Werkzeug did not properly handle certain web scripts. A remote attacker could use this to inject arbitrary code via a field that contains an exception message.
Update instructions: The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS:
python-werkzeug 0.10.4+dfsg1-1ubuntu1.1
python3-werkzeug 0.10.4+dfsg1-1ubuntu1.1
Ubuntu 14.04 LTS:
python-werkzeug 0.9.4+dfsg-1.1ubuntu2.1
python3-werkzeug 0.9.4+dfsg-1.1ubuntu2.1
Should we follow instructions as detailed on the bulletin and install the suggested package or are we having a LL update to resolve that?
Thanks in advance for your answers!
I just found this while I was checking this site which I use to visit regularly and was wondering whether if this Ubuntu Alert USN-3463-1 Werkzeug vulnerability is something we should worry about and if so, has it been taken care of already?.
The security bulletin says:
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
It was discovered that Werkzeug did not properly handle certain web scripts. A remote attacker could use this to inject arbitrary code via a field that contains an exception message.
Update instructions: The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS:
python-werkzeug 0.10.4+dfsg1-1ubuntu1.1
python3-werkzeug 0.10.4+dfsg1-1ubuntu1.1
Ubuntu 14.04 LTS:
python-werkzeug 0.9.4+dfsg-1.1ubuntu2.1
python3-werkzeug 0.9.4+dfsg-1.1ubuntu2.1
Should we follow instructions as detailed on the bulletin and install the suggested package or are we having a LL update to resolve that?
Thanks in advance for your answers!
Without each others help there ain't no hope for us
Need a translation service? https://www.deepl.com/es/translator
Need a translation service? https://www.deepl.com/es/translator