Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Mageia 7: MGASA-2019-0259 Critical: Python-urllib3 CRLF Injection

mageia
Calendar Grey September 6, 2019
Dist Mageia Esm H88
Recent updates to the python-urllib3 packages have successfully addressed critical CRLF injection vulnerabilities found in various Mageia distributions.
It was discovered that urllib3 incorrectly stripped certain characters from requests

Summary

It was discovered that urllib3 incorrectly stripped certain charactersfrom requests. A remote attacker could use this issue to perform CRLF injection (CVE-2019-11236).

References

- https://bugs.mageia.org/show_bug.cgi?id=23880

- https://ubuntu.com/security/notices/USN-3990-1

- https://www.cve.org/CVERecord?id=CVE-2019-11236

Resolution

SRPMS

- 7/core/python-urllib3-1.24.3-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0259.html
Type: security
CVE: CVE-2019-11236

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here