Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Mageia: 2020-0269 Moderate: httplib2 Request Header Manipulation

mageia
Calendar Grey July 4, 2020
Dist Mageia Esm H88
The latest python-httplib2 updates address critical security issues related to header manipulation and concealed request vulnerabilities.
Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers an...

Summary

Updated python-httplib2 packages fix security vulnerability:
In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping (CVE-2020-11078).

References

- https://bugs.mageia.org/show_bug.cgi?id=26750

- https://lists.debian.org/debian-lts-announce/2020/06/msg00000.html

- https://www.cve.org/CVERecord?id=CVE-2020-11078

Resolution

SRPMS

- 7/core/python-httplib2-0.18.0-1.mga7

Publication date: 04 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0269.html
Type: security
CVE: CVE-2020-11078

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here