/srv/irclogs.ubuntu.com/2021/09/27/#ubuntu-security.txt

=== ChanServ changed the topic of #ubuntu-security to: Twitter: @ubuntu_sec || https://usn.ubuntu.com || https://wiki.ubuntu.com/SecurityTeam || https://wiki.ubuntu.com/Security/Features || Community: mdeslaur
tomreynhi18:24
tomreynaccording to chat of user 'mythos' in #ubuntu, focal's python has lost a patch for CVE-2021-29921 as a result of the bug 1928057 SRU18:25
ubottuBug 1928057 in python3.8 (Ubuntu Groovy) "SRU: backport Python 3.8.10 to 20.04 LTS and 20.10" [Low, Fix Released] https://launchpad.net/bugs/192805718:25
ubottuIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. <https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29921>18:25
mdeslaurah ffs18:30
mdeslaurthanks tomreyn 18:30
tomreynyou're welcome. can this be automatically detected somehow?18:31
tomreyni'm wondering whether automated tests could be generated and run against new package versions18:32
mdeslaurthat would be nice18:34

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!