You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke python-urllib3

Sigurnosni nedostaci programske biblioteke python-urllib3

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LSU

openSUSE Security Update: Security update for python-urllib3
______________________________________________________________________________

Announcement ID: openSUSE-SU-2019:2133-1
Rating: moderate
References: #1129071 #1132663 #1132900
Cross-References: CVE-2019-11236 CVE-2019-11324 CVE-2019-9740

Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________

An update that fixes three vulnerabilities is now available.

Description:

This update for python-urllib3 fixes the following issues:

Security issues fixed:

– CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071).
– CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900).
– CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

– openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-2133=1

Package List:

– openSUSE Leap 15.1 (noarch):

python2-urllib3-1.24-lp151.2.3.1
python2-urllib3-test-1.24-lp151.2.3.1
python3-urllib3-1.24-lp151.2.3.1
python3-urllib3-test-1.24-lp151.2.3.1

References:

https://www.suse.com/security/cve/CVE-2019-11236.html
https://www.suse.com/security/cve/CVE-2019-11324.html
https://www.suse.com/security/cve/CVE-2019-9740.html
https://bugzilla.suse.com/1129071
https://bugzilla.suse.com/1132663
https://bugzilla.suse.com/1132900


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

openSUSE Security Update: Security update for python-urllib3
______________________________________________________________________________

Announcement ID: openSUSE-SU-2019:2131-1
Rating: moderate
References: #1119376 #1129071 #1132663 #1132900
Cross-References: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324
CVE-2019-9740
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________

An update that fixes four vulnerabilities is now available.

Description:

This update for python-urllib3 fixes the following issues:

Security issues fixed:

– CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071).
– CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900).
– CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663).
– CVE-2018-20060: Remove Authorization header when redirecting cross-host
(bsc#1119376).

This update was imported from the SUSE:SLE-15:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

– openSUSE Leap 15.0:

zypper in -t patch openSUSE-2019-2131=1

Package List:

– openSUSE Leap 15.0 (noarch):

python2-urllib3-1.22-lp150.5.3.1
python3-urllib3-1.22-lp150.5.3.1

References:

https://www.suse.com/security/cve/CVE-2018-20060.html
https://www.suse.com/security/cve/CVE-2019-11236.html
https://www.suse.com/security/cve/CVE-2019-11324.html
https://www.suse.com/security/cve/CVE-2019-9740.html
https://bugzilla.suse.com/1119376
https://bugzilla.suse.com/1129071
https://bugzilla.suse.com/1132663
https://bugzilla.suse.com/1132900


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

AutorJosip Papratovic
Cert idNCERT-REF-2019-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa go1.12

Otkriveni su sigurnosni nedostaci u programskom paketu go1.12 za operacijski sustav openSUSE. Otkriveni nedostaci potencijalnim napadačima omogućuju izazivanje DoS stanja...

Close