Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15.2: 2021:0772-1 Moderate: Fix Python Httplib2 DoS Issue

opensuse
Calendar Grey May 23, 2021
Dist Opensuse Esm H88
This release of Python httplib2 resolves important vulnerabilities, providing thorough installation guidance and risk assessments.
An update that fixes two vulnerabilities is now available

Description

This update for python-httplib2 contains the following fixes:

Security fixes included in this update:

- CVE-2021-21240: Fixed a regular expression denial of service via

malicious header (bsc#1182053).

- CVE-2020-11078: Fixed an issue where an attacker could change request

headers and body (bsc#1171998).

Non security fixes included in this update:

- Update in SLE to 0.19.0 (bsc#1182053, CVE-2021-21240)

- update to 0.19.0:

* auth: parse headers using pyparsing instead of regexp

* auth: WSSE token needs to be string not bytes

- update to 0.18.1: (bsc#1171998, CVE-2020-11078)

* explicit build-backend workaround for pip build isolation bug

* IMPORTANT security vulnerability CWE-93 CRLF injection Force %xx quote

of space, CR, LF characters in uri.

* Ship test suite in source dist

- Update to 0.17.1

* python3: no_proxy was not checked with https

* feature: Http().redirect_codes set, works after...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-772=1

Package List

- openSUSE Leap 15.2 (noarch):

python2-httplib2-0.19.0-lp152.6.3.1

python3-httplib2-0.19.0-lp152.6.3.1

References

https://www.suse.com/security/cve/CVE-2020-11078.html

https://www.suse.com/security/cve/CVE-2021-21240.html

https://bugzilla.suse.com/1171998

https://bugzilla.suse.com/1182053

Announcement ID: openSUSE-SU-2021:0772-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here