Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7 MGASA-2021-0055 Moderate: Python-urllib3 CRLF Injection Threat

mageia
Calendar Grey January 25, 2021
Dist Mageia Esm H88
Revamped python-urllib3 modules within Mageia 7 rectify the CRLF injection vulnerability outlined in MGASA-2021-0055.
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of put...

Summary

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (CVE-2020-26137).

References

- https://bugs.mageia.org/show_bug.cgi?id=27407

- https://ubuntu.com/security/notices/USN-4570-1

- https://www.cve.org/CVERecord?id=CVE-2020-26137

Resolution

SRPMS

- 7/core/python-urllib3-1.24.3-1.2.mga7

Publication date: 25 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0055.html
Type: security
CVE: CVE-2020-26137

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here