Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

SUSE: 2021:1779-1 Moderate Python-httplib2 Denial of Service Alert

suse
Calendar Grey May 27, 2021
Scroller Suse
The latest release of python-httplib2 rectifies vulnerabilities to improve overall system security. Ensure you verify for all patches and implement updates promptly.
An update that fixes two vulnerabilities is now available

Summary

This update for python-httplib2 contains the following fixes: Security fixes included in this update: - CVE-2021-21240: Fixed a regular expression denial of service via malicious header (bsc#1182053). - CVE-2020-11078: Fixed an issue where an attacker could change request headers and body (bsc#1171998). Non security fixes included in this update: - Update in SLE to 0.19.0 (bsc#1182053, CVE-2021-21240) - update to 0.19.0: * auth: parse headers using pyparsing instead of regexp * auth: WSSE token needs to be string not bytes - update to 0.18.1: (bsc#1171998, CVE-2020-11078) * explicit build-backend workaround for pip build isolation bug * IMPORTANT security vulnerability CWE-93 CRLF injection Force %xx quote of space, CR, LF characters in uri. * Ship test suite in source dist - update to 0.17.3: * bugfixes

References

#1171998 #1182053

Cross- CVE-2020-11078 CVE-2021-21240

CVSS scores:

CVE-2020-11078 (NVD) : 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

CVE-2020-11078 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N

CVE-2021-21240 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-21240 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud 9

https://www.suse.com/security/cve/CVE-2020-11078.html

https://www.suse.com/security/cve/CVE-2021-21240.html

https://bugzilla.suse.com/1171998

https://bugzilla.suse.com/1182053

Announcement ID: SUSE-SU-2021:1779-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.