Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia: 2018-0475 Critical: Python-Requests HTTP Header Exploit

mageia
Calendar Grey December 2, 2018
Dist Mageia Esm H88
The latest version of the python-requests library addresses vulnerabilities that could lead to the accidental exposure of confidential data through HTTP headers.
It was discovered that Requests incorrectly handled certain HTTP headers

Summary

It was discovered that Requests incorrectly handled certain HTTP headers. An attacker could possibly use this issue to access sensitive information (CVE-2018-18074).

References

- https://bugs.mageia.org/show_bug.cgi?id=23694

- https://ubuntu.com/security/notices/USN-3790-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ODR7ZTGPEISZ35PPEJLPU5CAE5D23CXV/

- https://www.cve.org/CVERecord?id=CVE-2018-18074

Resolution

SRPMS

- 6/core/python-requests-2.11.1-2.1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 02 Dec 2018
URL: https://advisories.mageia.org/MGASA-2018-0475.html
Type: security
CVE: CVE-2018-18074

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here