Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Ubuntu 18.10 USN-3790-2 Critical: Requests Sensitive Exposure

Ubuntu Large Esm H500
Requests could be made to expose sensitive information if it received a specially crafted HTTP header.
=========================================================================Ubuntu Security Notice USN-3790-2
October 22, 2018

requests vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10

Summary:

Requests could be made to expose sensitive information if it
received a specially crafted HTTP header.

Software Description:
- requests: elegant and simple HTTP library for Python

Details:

USN-3790-1 fixed vulnerabilities in Requests. This update provides
the corresponding update for Ubuntu 18.10

Original advisory details:

 It was discovered that Requests incorrectly handled certain HTTP
 headers. An attacker could possibly use this issue to access sensitive
 information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  python-requests                 2.18.4-2ubuntu0.18.10.1
  python3-requests                2.18.4-2ubuntu0.18.10.1

In general, a standard system update will make all the necessary
changes.

References:
  
  https://ubuntu.com/security/notices/USN-3790-1
  CVE-2018-18074

Package Information:
  https://launchpad.net/ubuntu/+source/requests/2.18.4-2ubuntu0.18.10.1

Ubuntu 18.10 USN-3790-2 Critical: Requests Sensitive Exposure

ubuntu
Calendar Grey October 22, 2018
Dist Ubuntu Esm H88
Uncover the weaknesses present in the Requests library on Ubuntu 18.10, along with the remedies detailed in USN-3790-2.
Requests could be made to expose sensitive information if it received a specially crafted HTTP header.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10:   python-requests                 2.18.4-2ubuntu0.18.10.1   python3-requests                2.18.4-2ubuntu0.18.10.1 In general, a standard system update will make all the necessary changes.

References

 

  https://ubuntu.com/security/notices/USN-3790-1

  CVE-2018-18074

Severity
critical
Lowest
Low
Medium
High
Critical

October 22, 2018

Package Information

  https://launchpad.net/ubuntu/+source/requests/2.18.4-2ubuntu0.18.10.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here