USN-5532-2: Bottle vulnerability
26 July 2022
Bottle could be made to leak sensitive information if it received a specially crafted request
Releases
Packages
- python-bottle - fast and simple WSGI-framework for Python
Details
USN-5532-1 fixed a vulnerability in Bottle. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM
Original advisory details:
It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitive
information. (CVE-2022-31799)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
python3-bottle
-
0.12.7-1+deb8u1ubuntu0.1~esm1
Available with Ubuntu Pro
-
python-bottle
-
0.12.7-1+deb8u1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
python3-bottle
-
0.12.0-1ubuntu0.1~esm3
Available with Ubuntu Pro
-
python-bottle
-
0.12.0-1ubuntu0.1~esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.