UbuntuUpdates.org

Bugs fixes in "python-urllib3"

Origin Bug number Title Date fixed
CVE CVE-2020-26137 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characte 2020-10-05
CVE CVE-2020-26137 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characte 2020-10-05
Debian 950738 python3-urllib3: Requires python3-six > 1.10.0-4 2020-04-23
Debian 938244 python-urllib3: Python2 removal in sid/bullseye 2020-04-23
Debian 950738 python3-urllib3: Requires python3-six > 1.10.0-4 2020-04-22
Debian 938244 python-urllib3: Python2 removal in sid/bullseye 2020-04-22
CVE CVE-2019-11236 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. 2019-05-21
CVE CVE-2018-20060 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho 2019-05-21
CVE CVE-2019-11236 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. 2019-05-21
CVE CVE-2018-20060 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho 2019-05-21
CVE CVE-2019-11324 The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA c 2019-05-21
CVE CVE-2019-11236 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. 2019-05-21
CVE CVE-2018-20060 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho 2019-05-21
CVE CVE-2019-11324 The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA c 2019-05-21
CVE CVE-2019-11236 In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. 2019-05-21
CVE CVE-2018-20060 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho 2019-05-21
Launchpad 1771988 certificate validation with IP address based SAN's fails 2018-08-30
Launchpad 1771988 certificate validation with IP address based SAN's fails 2018-08-22
Launchpad 1578351 mitaka ksclient fails to connect to v6 keystone 2016-05-19
Launchpad 1578351 mitaka ksclient fails to connect to v6 keystone 2016-05-12



About   -   Send Feedback to @ubuntu_updates