LINUX LITE 7.2 FINAL RELEASED - SEE RELEASE ANNOUNCEMENTS SECTION FOR DETAILS


Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Ubuntu alert USN-3463-1 (python-werkzeug)
#1
Hi everyone! Hope you're all having a nice life! Smile
I just found this while I was checking this site which I use to visit regularly and was wondering whether  if this Ubuntu Alert USN-3463-1 Werkzeug vulnerability is something we should worry about and if so, has it been taken care of already?.

The security bulletin  says:
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

It was discovered that Werkzeug did not properly handle certain web scripts. A remote attacker could use this to inject arbitrary code via a field that contains an exception message.

Update instructions: The problem can be corrected by updating your system to the following package versions:

Ubuntu 16.04 LTS:
python-werkzeug          0.10.4+dfsg1-1ubuntu1.1
python3-werkzeug        0.10.4+dfsg1-1ubuntu1.1

Ubuntu 14.04 LTS: 
python-werkzeug          0.9.4+dfsg-1.1ubuntu2.1
python3-werkzeug        0.9.4+dfsg-1.1ubuntu2.1


Should we follow instructions as detailed on the bulletin and install the suggested package or are we having a LL update to resolve that?
Thanks in advance for your answers! Smile
Without each others help there ain't no hope for us Smile
Need a translation service? https://www.deepl.com/es/translator
Reply


Messages In This Thread
Ubuntu alert USN-3463-1 (python-werkzeug) - by Moltke - 10-27-2017, 03:58 AM

Forum Jump:


Users browsing this thread: 2 Guest(s)