Debian: DSA-3942-1: supervisor security update
Summary
The vulnerability has been fixed by disabling nested namespace lookup
entirely. supervisord will now only call methods on the object
registered to handle XML-RPC requests and not any child objects it may
contain, possibly breaking existing setups. No publicly available
plugins are currently known that use nested namespaces. Plugins that use
a single namespace will continue to work as before. Details can be found
on the upstream issue at
https://github.com/Supervisor/supervisor/issues/964 .
For the oldstable distribution (jessie), this problem has been fixed
in version 3.0r1-1+deb8u1.
For the stable distribution (stretch), this problem has been fixed in
version 3.3.1-1+deb9u1.
We recommend that you upgrade your supervisor packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/