Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2019:0139-1 Moderate: python-urllib3 TLS Certificate Issue

suse
Calendar Grey January 21, 2019
Dist Suse Esm H88
SUSE Security Update: Security update for python-urllib3 ___________________________________________
An update that solves one vulnerability and has two fixes is now available

Summary

This update for python-urllib3 fixes the following issues: python-urllib3 was updated to version 1.22 (fate#326733, bsc#1110422) and contains new features and lots of bugfixes: The full changelog can be found on: https://github.com/Lukasa/urllib3/blob/1.22/CHANGES.rst Security issues fixed: - CVE-2016-9015: TLS certificate validation vulnerability (bsc#1024540). (This issue did not affect our previous version 1.16.) Non security issues fixed: - bsc#1074247: Fix test suite, use correct date (gh#shazow/urllib3#1303). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 3.2:

References

#1024540 #1074247 #1110422

Cross- CVE-2016-9015

Affected Products:

SUSE Manager Server 3.2

SUSE Manager Server 3.1

SUSE Linux Enterprise Module for Public Cloud 12

SUSE Enterprise Storage 5

SUSE Enterprise Storage 4

SUSE CaaS Platform ALL

SUSE CaaS Platform 3.0

OpenStack Cloud Magnum Orchestration 7

https://www.suse.com/security/cve/CVE-2016-9015.html

https://bugzilla.suse.com/1024540

https://bugzilla.suse.com/1074247

https://bugzilla.suse.com/1110422

Severity
medium
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0139-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here