MGASA-2018-0475 - Updated python-requests packages fix security vulnerability

Publication date: 02 Dec 2018
URL: https://advisories.mageia.org/MGASA-2018-0475.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-18074

It was discovered that Requests incorrectly handled certain HTTP
headers. An attacker could possibly use this issue to access sensitive
information (CVE-2018-18074).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23694
- https://ubuntu.com/security/notices/USN-3790-1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ODR7ZTGPEISZ35PPEJLPU5CAE5D23CXV/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18074

SRPMS:
- 6/core/python-requests-2.11.1-2.1.mga6

Mageia 2018-0475: python-requests security update

It was discovered that Requests incorrectly handled certain HTTP headers

Summary

It was discovered that Requests incorrectly handled certain HTTP headers. An attacker could possibly use this issue to access sensitive information (CVE-2018-18074).

References

- https://bugs.mageia.org/show_bug.cgi?id=23694

- https://ubuntu.com/security/notices/USN-3790-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ODR7ZTGPEISZ35PPEJLPU5CAE5D23CXV/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18074

Resolution

MGASA-2018-0475 - Updated python-requests packages fix security vulnerability

SRPMS

- 6/core/python-requests-2.11.1-2.1.mga6

Severity
Publication date: 02 Dec 2018
URL: https://advisories.mageia.org/MGASA-2018-0475.html
Type: security
CVE: CVE-2018-18074

Related News