USN-6991-1: AIOHTTP vulnerability
5 September 2024
python-aiohttp would allow unintended access to files over the network.
Releases
Packages
- python-aiohttp - http client/server for asyncio
Details
It was discovered that AIOHTTP did not properly restrict file access when
the 'follow_symlinks' option was set to True. A remote attacker could
possibly use this issue to access unauthorized files on the system.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 22.04
Ubuntu 20.04
-
python3-aiohttp
-
3.6.2-1ubuntu1+esm3
Available with Ubuntu Pro
Ubuntu 18.04
-
python3-aiohttp
-
3.0.1-1ubuntu0.1~esm4
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.