-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4780-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
September 15, 2026                            https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : urwid
Version        : 2.1.2-4+deb12u1
CVE ID         : CVE-2026-9323


The urwid web display backend generates web session identifiers by
concatenating two random.randrange(10**9) calls that use Python's
Mersenne Twister PRNG, which is not cryptographically secure. The same
identifier is also used as the filename of a FIFO created in the
world-listable /tmp directory, so any local user on the host can list
/tmp to enumerate active session tokens directly. With a valid session
ID, an attacker can read the victim's terminal screen via the polling
endpoint, inject keystrokes into the victim's session, and inject exit
sequences or flood the FIFO to terminate or crash the session.

For Debian 12 bookworm, this problem has been fixed in version
2.1.2-4+deb12u1.

We recommend that you upgrade your urwid packages.

For the detailed security status of urwid please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/urwid

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqo3ZgACgkQhj1N8u2c
KO9ksQ//fVlUR7u/akjrDcMkosAn9I2Z+rZBIBcKjgw4YTbFBYI08UI/ZmwPkz97
AQtqrrXuTL3xKuwl6sUhZ28ECDxwVwkUcjwaTRkWpyFyB3jRkkXRjP9IpFhWKI7f
DrV68px9c554lb1ATxVbRJ1fT5R/V2lUsA2i10Y+k0p6TKjDFnI1RXwdtA+139H/
stFCBLiLgknufl/KNVs73A8ipHWiTDpsI8wBJ6iogZj8pLkkKb/u/95vo+25rMMw
MkCXk3GPuRFGw/k2xyis0cViDU0hFF7gA2IfqouS8mnMuhCwn5hhRFnbnm7qeRa4
5CYaM/6kOQOkLTX4coIbzraax33NZ7VTY3nwUQLDn5FnC7EgVmjNv0awdpJft/Hq
Wi2+Xc2om2nNRWBaPc4kEehd+h1nDxx//0PAlUSqWEih66NwupEZht7iqlSSnh8d
SynIQA8If+xajHxrulbhFkDU+bSdQiYqu/1m+btwkxgYbx37+zIBSpDQrrC005Eh
0pmrKqCIwTFR6c6et6u7sjygJidxPcscR9tL1viDzDCi0Np1HZRxnbqPA8egm4uF
xjrW9Km7CYM/QselHhG4a3Mg71XrdvhH5Mj8aTPEpLuUlygavUSG9BMrAxpt1aYY
9R90iimG7aj1veVInbbv57Rr1lA9bqILkiOvj94bquuIFvCx+PM=
=/clh
-----END PGP SIGNATURE-----

Reply via email to