USN-7216-1: tqdm vulnerability
16 January 2025
tqdm could be made to crash or to allow arbitary code execution if it received specially crafted input.
Releases
Packages
- tqdm - fast, extensible progress bar for Python 3 and CLI tool
Details
It was discovered that tqdm did not properly sanitize non-boolean CLI
Arguments. A local attacker could possibly use this issue to execute
arbitrary code on the host. This issue only affected Ubuntu 22.04 LTS and
Ubuntu 24.04 LTS. (CVE-2024-34062)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
-
python3-tqdm
-
4.66.2-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04
-
python3-tqdm
-
4.57.0-2ubuntu0.1~esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.