BugTraq
[SECURITY] [DSA 3146-1] requests security update Jan 30 2015 03:54PM
Sebastien Delafond (seb debian org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- ------------------------------------------------------------------------
-
Debian Security Advisory DSA-3146-1 security (at) debian (dot) org [email concealed]
http://www.debian.org/security/ Sebastien Delafond
January 30, 2015 http://www.debian.org/security/faq
- ------------------------------------------------------------------------
-

Package : requests
CVE ID : CVE-2014-1829 CVE-2014-1830
Debian Bug : 733108

Jakub Wilk discovered that in requests, an HTTP library for the Python
language, authentication information was improperly handled when a
redirect occured. This would allow remote servers to obtain two
different types of sensitive information: proxy passwords from the
Proxy-Authorization header (CVE-2014-1830), or netrc passwords from
the Authorization header (CVE-2014-1829).

For the stable distribution (wheezy), this problem has been fixed in
version 0.12.1-1+deb7u1.

For the upcoming stable distribution (jessie) and unstable
distribution (sid), this problem has been fixed in version 2.3.0-1.

We recommend that you upgrade your requests packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce (at) lists.debian (dot) org [email concealed]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJUy49eAAoJEBC+iYPz1Z1k9NkH/0gfqT+iVAg7eEUv45Cq+2eC
GhqAK4kWssYQQ9TxjUm2jC+5ACMzqP5wNTCu9LZHeAYv08MXd+D+kcmCgyUKpd6T
TE12DbO8fdW9Kos6al4vukxmDCOemXYmX2XDzzCw2hUk1g3Qummh7lB2M2vjs7o3
IcRo05HLh97qbulduPD0lmsU8na4NNPItTQMqtBn6uCp35AANTxNyDlzxxl3qKhq
WoCzVFWU+S0Z44k2laqp8yxOlNnTGoMH3inQL74T5jIhWGNNKntFZJf4HD252OH3
snoscPYNVldRteJ2uyzxOY95x0ybn46fvTk76Mno9tVoxjfDq9UWTb/Xt3+lFDo=
=0AoF
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus