========================================================================== Ubuntu Security Notice USN-5713-1 November 03, 2022 python3.10 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS Summary: Python could be made to run programs if it received specially crafted socket connections. Software Description: - python3.10: An interactive high-level object-oriented language Details: Devin Jeanpierre discovered that Python incorrectly handled sockets when the multiprocessing module was being used. A local attacker could possibly use this issue to execute arbitrary code and escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3.10 3.10.7-1ubuntu0.1 python3.10-minimal 3.10.7-1ubuntu0.1 Ubuntu 22.04 LTS: python3.10 3.10.6-1~22.04.1 python3.10-minimal 3.10.6-1~22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5713-1 CVE-2022-42919 Package Information: https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1 https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1