Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Nvidia GeForce GTX 1660 Ti Reviews and more
· NVIDIA 418.43 Linux Display Drivers released
· Windows 10 Insider Preview Build 18343 and Build 18841 released
· NVIDIA Geforce Game Ready Driver 419.17 WHQL
· Iscsi-initiator-utils Bug Fix Update for Oracle Linux 6
· Rssh Security Update for Debian 9
· Bind Security Update for Ubuntu Linux
· Build, Mosquitto, Nodejs6, GraphicsMagick Updates for openSUSE
· Adrenalin Software Edition 19.2.2 Driver Performance Analysis using the Red Devil RX 590 and more
· GNOME 3.32 Beta 2 released

Linux Compatibility
· Brother DCP-L2540DN
· Sound Blaster E5
· WD Elements 500GB external hard drive
· Canon D660U Flatbad scanner
· Umax Astra 4500 USB Scanner
· Logitech QuickCam Pro 4000
· Dell Latitude E6420
· Creative Sound Blaster Z
· Photosmart 5520
· TB-5300 Slimline Design Tablet

New Forum Topics
· Dale
by: Dale Blinco
on: 2018-02-05 00:26
1 replies, 4051 views

· modem driver needed
by: jongiffen777
on: 2017-12-13 11:11
1 replies, 5790 views

· Need a decent browser for XP Pro!
by: percy
on: 2017-12-05 11:02
2 replies, 7191 views

· Comodo Time Machine + Faronics Deep Freeze
by: Jabberwocky
on: 2017-11-15 23:17
1 replies, 5706 views

· Linux compatablity
by: ibme
on: 2017-10-04 18:05
1 replies, 7644 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android
· Oracle Linux
· Arch Linux

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » December 2018 » Jupyter-notebook Update for Arch Linux

Jupyter-notebook Update for Arch Linux

Posted by Philipp Esselbach on: 12/07/2018 09:51 AM [ Print | 0 comment(s) ]

Updated jupyter-notebook packages has been released for Arch Linux




Arch Linux Security Advisory ASA-201812-1
=========================================

Severity: Medium
Date : 2018-12-06
CVE-ID : CVE-2018-19351 CVE-2018-19352
Package : jupyter-notebook
Type : cross-site scripting
Remote : No
Link : https://security.archlinux.org/AVG-820

Summary
=======

The package jupyter-notebook before version 5.7.2-1 is vulnerable to
cross-site scripting.

Resolution
==========

Upgrade to 5.7.2-1.

# pacman -Syu "jupyter-notebook>=5.7.2-1"

The problems have been fixed upstream in version 5.7.2.

Workaround
==========

None.

Description
===========

- CVE-2018-19351 (cross-site scripting)

A security issue has been found in Jupyter Notebook versions prior to
5.7.1, where untrusted javascript could be executed if malicious files
could be delivered to the users system and the user takes specific
actions with those malicious files. It allowed nbconvert endpoints
(such as Print Preview) to render untrusted HTML and javascript with
access to the notebook server.

- CVE-2018-19352 (cross-site scripting)

A security issue has been found in Jupyter Notebook versions prior to
5.7.2, where untrusted javascript could be executed if malicious files
could be delivered to the users system and the user takes specific
actions with those malicious files. It allowed maliciously crafted
directory names to execute javascript when opened in the tree view.

Impact
======

A remote attacker is able to execute javascript and create html content
by tricking users into opening and interacting with maliciously crafted
notebook files.

References
==========

https://bugs.archlinux.org/task/60910
https://blog.jupyter.org/jupyter-notebook-security-fixes-59817e86a711
https://blog.jupyter.org/security-fix-for-jupyter-notebook-450f272b6932?gi=dbc3ae28c796
https://security.archlinux.org/CVE-2018-19351
https://security.archlinux.org/CVE-2018-19352


Jupyter-notebook Update for Arch Linux

« EDE Security Update for Gentoo · Gluster 5 for CentOS Linux 7 x86_64 released »

Linux Compatible » News » December 2018 » Jupyter-notebook Update for Arch Linux
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2018 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition