USN-7348-1

Source
https://ubuntu.com/security/notices/USN-7348-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7348-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7348-1
Related
Published
2025-03-12T14:36:24.233754Z
Modified
2025-03-12T14:36:24.233754Z
Summary
python3.5, python3.8 vulnerabilities
Details

It was discovered that the Python ipaddress module contained incorrect information about which IP address ranges were considered “private” or “globally reachable”. This could possibly result in applications applying incorrect security policies. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-4032)

It was discovered that Python incorrectly handled quoting path names when using the venv module. A local attacker able to control virtual environments could possibly use this issue to execute arbitrary code when the virtual environment is activated. (CVE-2024-9287)

It was discovered that Python incorrectly handled parsing bracketed hosts. A remote attacker could possibly use this issue to perform a Server-Side Request Forgery (SSRF) attack. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-11168)

It was discovered that Python incorrectly handled parsing domain names that included square brackets. A remote attacker could possibly use this issue to perform a Server-Side Request Forgery (SSRF) attack. (CVE-2025-0938)

References

Affected packages

Ubuntu:Pro:14.04:LTS / python3.5

Package

Name
python3.5
Purl
pkg:deb/ubuntu/python3.5@3.5.2-2ubuntu0~16.04.4~14.04.1+esm4?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.2-2ubuntu0~16.04.4~14.04.1+esm4

Affected versions

3.*

3.5.2-2ubuntu0~16.04.4~14.04.1
3.5.2-2ubuntu0~16.04.4~14.04.1+esm1
3.5.2-2ubuntu0~16.04.4~14.04.1+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "idle-python3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-dbg"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-dev"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-dev-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-minimal"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-minimal-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-stdlib"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-stdlib-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "libpython3.5-testsuite"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-dbg"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-dev"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-dev-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-doc"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-examples"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-minimal"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-minimal-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-venv"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.4~14.04.1+esm4",
            "binary_name": "python3.5-venv-dbgsym"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / python3.5

Package

Name
python3.5
Purl
pkg:deb/ubuntu/python3.5@3.5.2-2ubuntu0~16.04.13+esm16?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.2-2ubuntu0~16.04.13+esm16

Affected versions

3.*

3.5.0-3
3.5.0-3ubuntu1
3.5.1~rc1-2ubuntu1
3.5.1-1
3.5.1-2
3.5.1-3
3.5.1-5
3.5.1-6ubuntu1
3.5.1-6ubuntu2
3.5.1-9ubuntu1
3.5.1-10
3.5.2-2~16.01
3.5.2-2~16.04
3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.2
3.5.2-2ubuntu0~16.04.3
3.5.2-2ubuntu0~16.04.4
3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.8
3.5.2-2ubuntu0~16.04.9
3.5.2-2ubuntu0~16.04.10
3.5.2-2ubuntu0~16.04.11
3.5.2-2ubuntu0~16.04.12
3.5.2-2ubuntu0~16.04.13
3.5.2-2ubuntu0~16.04.13+esm1
3.5.2-2ubuntu0~16.04.13+esm2
3.5.2-2ubuntu0~16.04.13+esm3
3.5.2-2ubuntu0~16.04.13+esm5
3.5.2-2ubuntu0~16.04.13+esm6
3.5.2-2ubuntu0~16.04.13+esm7
3.5.2-2ubuntu0~16.04.13+esm8
3.5.2-2ubuntu0~16.04.13+esm9
3.5.2-2ubuntu0~16.04.13+esm10
3.5.2-2ubuntu0~16.04.13+esm11
3.5.2-2ubuntu0~16.04.13+esm12
3.5.2-2ubuntu0~16.04.13+esm13
3.5.2-2ubuntu0~16.04.13+esm14
3.5.2-2ubuntu0~16.04.13+esm15

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "idle-python3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-dbg"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-dev"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-dev-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-minimal"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-minimal-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-stdlib"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-stdlib-dbgsym"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "libpython3.5-testsuite"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-dbg"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-dev"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-doc"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-examples"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-minimal"
        },
        {
            "binary_version": "3.5.2-2ubuntu0~16.04.13+esm16",
            "binary_name": "python3.5-venv"
        }
    ]
}

Ubuntu:20.04:LTS / python3.8

Package

Name
python3.8
Purl
pkg:deb/ubuntu/python3.8@3.8.10-0ubuntu1~20.04.16?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.8.10-0ubuntu1~20.04.16

Affected versions

3.*

3.8.0-1
3.8.0-2
3.8.0-3
3.8.0-4
3.8.0-5
3.8.1-2ubuntu3
3.8.2~rc1-1ubuntu1
3.8.2-1
3.8.2-1ubuntu1
3.8.2-1ubuntu1.1
3.8.2-1ubuntu1.2
3.8.5-1~20.04
3.8.5-1~20.04.2
3.8.5-1~20.04.3
3.8.10-0ubuntu1~20.04
3.8.10-0ubuntu1~20.04.1
3.8.10-0ubuntu1~20.04.2
3.8.10-0ubuntu1~20.04.4
3.8.10-0ubuntu1~20.04.5
3.8.10-0ubuntu1~20.04.6
3.8.10-0ubuntu1~20.04.7
3.8.10-0ubuntu1~20.04.8
3.8.10-0ubuntu1~20.04.9
3.8.10-0ubuntu1~20.04.10
3.8.10-0ubuntu1~20.04.11
3.8.10-0ubuntu1~20.04.12
3.8.10-0ubuntu1~20.04.13
3.8.10-0ubuntu1~20.04.14
3.8.10-0ubuntu1~20.04.15

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "idle-python3.8"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8-dbg"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8-dev"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8-minimal"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8-stdlib"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "libpython3.8-testsuite"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-dbg"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-dev"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-doc"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-examples"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-full"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-minimal"
        },
        {
            "binary_version": "3.8.10-0ubuntu1~20.04.16",
            "binary_name": "python3.8-venv"
        }
    ]
}