CVE-2024-6345
Publication date 15 July 2024
Last updated 20 September 2024
Ubuntu priority
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
Status
Package | Ubuntu Release | Status |
---|---|---|
python-pip | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Fixed 20.0.2-5ubuntu1.10+esm2
|
|
18.04 LTS bionic |
Fixed 9.0.1-2.3~ubuntu1.18.04.8+esm4
|
|
16.04 LTS xenial |
Fixed 8.1.1-2ubuntu0.6+esm8
|
|
14.04 LTS trusty |
Fixed 1.5.4-1ubuntu4+esm5
|
|
python-setuptools | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Fixed 44.1.1-1.2ubuntu0.22.04.1+esm1
|
|
20.04 LTS focal |
Fixed 44.0.0-2ubuntu0.1+esm1
|
|
18.04 LTS bionic |
Fixed 39.0.1-2ubuntu0.1+esm1
|
|
16.04 LTS xenial |
Fixed 20.7.0-1ubuntu0.1~esm2
|
|
14.04 LTS trusty |
Fixed 3.3-1ubuntu2+esm2
|
|
setuptools | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Fixed 68.1.2-2ubuntu1.1
|
|
22.04 LTS jammy |
Fixed 59.6.0-1.2ubuntu0.22.04.2
|
|
20.04 LTS focal |
Fixed 45.2.0-1ubuntu0.2
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
mdeslaur
On focal and earlier, the python-pip package bundles python-setuptools binaries when built. After updating python-setuptools, a no-change rebuild of python-pip is required. On jammy and later, python-setuptools is bundled in the python-pip package and needs to be patched.
References
Related Ubuntu Security Notices (USN)
- USN-7002-1
- Setuptools vulnerability
- 12 September 2024