Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian DSA-3146-1 Critical: Authentication Issues in Requests Library

debian
Calendar Grey January 30, 2015
Debian Logo
Uncover the details of the January 2015 Debian Security Announcement DSA-3146-1 concerning a vulnerability related to sensitive data exposure in the requests package.
Jakub Wilk discovered that in requests, an HTTP library for the Python language, authentication information was improperly handled when a redirect occured

Summary

For the stable distribution (wheezy), this problem has been fixed in
version 0.12.1-1+deb7u1.

For the upcoming stable distribution (jessie) and unstable
distribution (sid), this problem has been fixed in version 2.3.0-1.

We recommend that you upgrade your requests packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: requests
CVE ID: CVE-2014-1829 CVE-2014-1830

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here