MGASA-2021-0054 - Updated python-pip packages fix security vulnerabilities

Publication date: 25 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0054.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-20916,
     CVE-2020-26137

It was discovered that pip did not properly sanitize the filename during pip
install. A remote attacker could possible use this issue to read and write
arbitrary files on the host filesystem as root, resulting in a directory
traversal attack (CVE-2019-20916).

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP
request method, as demonstrated by inserting CR and LF control characters in
the first argument of putrequest(). The python-pip package bundles a copy of
python-urllib3, which was affected by this issue.  The bundled copy was
patched to fix the issue (CVE-2020-26137).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27301
- https://bugs.mageia.org/show_bug.cgi?id=27407
- https://ubuntu.com/security/notices/USN-4601-1
- https://ubuntu.com/security/notices/USN-4570-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20916
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26137

SRPMS:
- 7/core/python-pip-19.0.3-1.3.mga7

Mageia 2021-0054: python-pip security update

It was discovered that pip did not properly sanitize the filename during pip install

Summary

It was discovered that pip did not properly sanitize the filename during pip install. A remote attacker could possible use this issue to read and write arbitrary files on the host filesystem as root, resulting in a directory traversal attack (CVE-2019-20916).
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). The python-pip package bundles a copy of python-urllib3, which was affected by this issue. The bundled copy was patched to fix the issue (CVE-2020-26137).

References

- https://bugs.mageia.org/show_bug.cgi?id=27301

- https://bugs.mageia.org/show_bug.cgi?id=27407

- https://ubuntu.com/security/notices/USN-4601-1

- https://ubuntu.com/security/notices/USN-4570-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20916

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26137

Resolution

MGASA-2021-0054 - Updated python-pip packages fix security vulnerabilities

SRPMS

- 7/core/python-pip-19.0.3-1.3.mga7

Severity
Publication date: 25 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0054.html
Type: security
CVE: CVE-2019-20916, CVE-2020-26137

Related News