Ubuntu Security Update USN-8344-3: pip vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,792
Reaction score
74
Credits
-1,257
USN-8344-1 introduced a regression in pip. This update provides a complete fix for this issue.. We apologize for the inconvenience. Original advisory details: It was discovered that pip's bundled urllib3 library improperly handled streaming decompression of highly compressed data. A remote attacker could possibly use this issue to cause pip to consume excessive resources, leading to a denial of service. (CVE-2025-66471)

Continue reading...
 
Top