USN-7348-1 fixed vulnerabilities in Python. The update introduced a
regression. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python ipaddress module contained incorrect
information about which IP address ranges were considered “private” or
“globally reachable”. This could possibly result in applications applying
incorrect security policies. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-4032)
It was discovered that Python incorrectly handled quoting path names when
using the venv module. A local attacker able to control virtual
environments could possibly use this issue to execute arbitrary code when
the virtual environment is activated. (CVE-2024-9287)
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected Ubuntu 14.04 LTS
and Ubuntu 16.04 LTS. (CVE-2024-11168)
It was discovered that Python incorrectly handled parsing domain names that
included square brackets. A remote attacker could possibly use this issue
to perform a Server-Side Request Forgery (SSRF) attack. (CVE-2025-0938)
More Stories
Apache Tomcat RCE
What is the Vulnerability?On March 10, 2025, Apache issued a security advisory regarding a critical vulnerability (CVE-2025-24813) affecting the Apache...
USN-7375-1: Org Mode vulnerabilities
It was discovered that Org Mode did not correctly handle filenames containing shell metacharacters. An attacker could possibly use this...
USN-7374-1: containerd vulnerability
Benjamin Koltermann discovered that containerd incorrectly handled large user id values. This could result in containers possibly being run as...
exim-4.98.2-1.el8
FEDORA-EPEL-2025-9b4f4b88ff Packages in this update: exim-4.98.2-1.el8 Update description: This is update fixing CVE 2025-30232. Read More
exim-4.98.2-1.el9
FEDORA-EPEL-2025-ff88bfea14 Packages in this update: exim-4.98.2-1.el9 Update description: This is an update fixing CVE 2025-30232. Read More
exim-4.98.2-1.fc40
FEDORA-2025-3a56fe6159 Packages in this update: exim-4.98.2-1.fc40 Update description: This is an update fixing CVE 2025-30232. Read More