Ubuntu Security Notice 4655-1 - It was discovered that Werkzeug has insufficient debugger PIN randomness. An attacker could use this issue to access sensitive information. This issue only affected Ubuntu 18.04 LTS. It was discovered that Werkzeug incorrectly handled certain URLs. An attacker could possibly use this issue to cause phishing attacks. This issue only affected Ubuntu 16.04 LTS.
f963003ef70151c4a9f12cf38a0eec8d7635ae2186a53f0a5acf8f9c12171fca
=========================================================================
Ubuntu Security Notice USN-4655-1
December 01, 2020
python-werkzeug vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Werkzeug.
Software Description:
- python-werkzeug: collection of utilities for WSGI applications (Python 2.x)
Details:
It was discovered that Werkzeug has insufficient debugger PIN randomness.
An attacker could use this issue to access sensitive information. This issue only
affected Ubuntu 18.04 LTS. (CVE-2019-14806)
It was discovered that Werkzeug incorrectly handled certain URLs.
An attacker could possibly use this issue to cause pishing attacks.
This issue only affected Ubuntu 16.04 LTS. (CVE-2020-28724)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
python-werkzeug 0.14.1+dfsg1-1ubuntu0.1
python3-werkzeug 0.14.1+dfsg1-1ubuntu0.1
Ubuntu 16.04 LTS:
python-werkzeug 0.10.4+dfsg1-1ubuntu1.2
python3-werkzeug 0.10.4+dfsg1-1ubuntu1.2
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4655-1
CVE-2019-14806, CVE-2020-28724
Package Information:
https://launchpad.net/ubuntu/+source/python-werkzeug/0.14.1+dfsg1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/python-werkzeug/0.10.4+dfsg1-1ubuntu1.2