An update that solves two vulnerabilities and has 10 fixes is now available. . SUSE Security Update: Security update for python3-requests ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1792-1 Rating: moderate References: #1054413 #1073879 #1111622 #1122668 #761500 #922448 #929736 #935252 #945455 #947357 #961596 #967128 Cross-References: CVE-2015-2296 CVE-2018-18074 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Manager Server 3.2 SUSE Manager Proxy 3.2 SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Module for Public Cloud 12 SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that solves two vulnerabilities and has 10 fixes is now available. Description: This update for python3-requests provides the following fix: python-requests was updated to 2.20.1. Update to version 2.20.1: * Fixed bug with unintended Authorization header stripping for redirects using default ports (http/80, https/443). Update to version 2.20.0: * Bugfixes + Content-Type headerparsing is now case-insensitive (e.g. charset=utf8 v Charset=utf8). + Fixed exception leak where certain redirect urls would raise uncaught urllib3 exceptions. + Requests removes Authorization header from requests redirected from https to http on the same hostname. (CVE-2018-18074) + should_bypass_proxies now handles URIs without hostnames (e.g. files). Update to version 2.19.1: * Fixed issue where status_codes.py’s init function failed trying to append to a __doc__ value of None. Update to version 2.19.0: * Improvements + Warn about possible slowdown with cryptography version < 1.3.4 + Check host in proxy URL, before forwarding request to adapter. + Maintain fragments properly across redirects. (RFC7231 7.1.2) + Removed use of cgi module to expedite library load time. + Added support for SHA-256 and SHA-512 digest auth algorithms. + Minor performance improvement to Request.content. * Bugfixes + Parsing empty Link headers with parse_header_links() no longer return one bogus entry. + Fixed issue where loading the default certificate bundle from a zip archive would raise an IOError. + Fixed issue with unexpected ImportError on windows system which do not support winreg module. + DNS resolution in proxy bypass no longer includes the username and password in the request. This also fixes the issue of DNS queries failing on macOS. + Properly normalize adapter prefixes for url comparison. + Passing None as a file pointer to the files param no longer raises an exception. + Calling copy on a RequestsCookieJar will now preserve the cookie policy correctly. Update to version 2.18.4: * Improvements + Error messages for invalid headers now include the header name for easier debugging Update to version 2.18.3: * Improvements + Running $ python -m requests.help now includes the installed version of idna. *Bugfixes + Fixed issue where Requests would raise ConnectionError instead of SSLError when encountering SSL problems when using urllib3 v1.22. - Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https connections will fail. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-1792=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-1792=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-1792=1 - SUSE Manager Server 3.2: zypper in -t patch SUSE-SUSE-Manager-Server-3.2-2020-1792=1 - SUSE Manager Proxy 3.2: zypper in -t patch SUSE-SUSE-Manager-Proxy-3.2-2020-1792=1 - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2020-1792=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-1792=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-1792=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-1792=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-1792=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-1792=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-1792=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-1792=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-1792=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patchSUSE-SLE-SERVER-12-SP2-BCL-2020-1792=1 - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2020-1792=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-1792=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-1792=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE OpenStack Cloud 8 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE OpenStack Cloud 7 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Manager Server 3.2 (noarch): python-certifi-2018.4.16-3.6.1 python-chardet-3.0.4-5.6.1 python-urllib3-1.22-3.20.1 python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Manager Proxy 3.2 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Workstation Extension 12-SP5 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server for SAP 12-SP2(noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): python-certifi-2018.4.16-3.6.1 python-chardet-3.0.4-5.6.1 python-urllib3-1.22-3.20.1 python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP4 (noarch): python-chardet-3.0.4-5.6.1 python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-certifi-2018.4.16-3.6.1 python-chardet-3.0.4-5.6.1 python-urllib3-1.22-3.20.1 python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-urllib3-1.22-3.20.1 - SUSE Enterprise Storage 5 (noarch): python-urllib3-1.22-3.20.1 python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 - HPE Helion Openstack 8 (noarch): python3-certifi-2018.4.16-3.6.1 python3-chardet-3.0.4-5.6.1 python3-requests-2.20.1-5.2 python3-urllib3-1.22-3.20.1 References: https://www.suse.com/security/cve/CVE-2015-2296.html https://www.suse.com/security/cve/CVE-2018-18074.html https://bugzilla.suse.com/1054413 https://bugzilla.suse.com/1073879 https://bugzilla.suse.com/1111622 https://bugzilla.suse.com/1122668 https://bugzilla.suse.com/761500 https://bugzilla.suse.com/922448 https://bugzilla.suse.com/929736 https://bugzilla.suse.com/935252 https://bugzilla.suse.com/945455 https://bugzilla.suse.com/947357 https://bugzilla.suse.com/961596 https://bugzilla.suse.com/967128 . SUSE has released a Security Update for python3-requests, addressing key vulnerabilities with essential fixes. Discover further details.. Suse Security Update, Python3 Requests, Authorization Bug, Software Patch. . Severity: Important. LinuxSecurity.com Team
An update for python-virtualenv is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: python-virtualenv security update Advisory ID: RHSA-2020:0851-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:0851 Issue date: 2020-03-17 CVE Names: CVE-2018-18074 CVE-2018-20060 CVE-2019-11236 ==================================================================== 1. Summary: An update for python-virtualenv is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - noarch Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: The virtualenv tool creates isolated Python environments. The virtualenv tool is a successor to workingenv, and an extension of virtual-python. Security Fix(es): * python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure (CVE-2018-20060) * python-urllib3: CRLF injection due to not encoding the ' ' sequence leading to possible attack on internal service (CVE-2019-11236) * python-requests: Redirect from HTTPS to HTTP does not remove Authorization header (CVE-2018-18074) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and otherrelated information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1643829 - CVE-2018-18074 python-requests: Redirect from HTTPS to HTTP does not remove Authorization header 1649153 - CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure 1700824 - CVE-2019-11236 python-urllib3: CRLF injection due to not encoding the ' ' sequence leading to possible attack on internal service 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: python-virtualenv-15.1.0-4.el7_7.src.rpm noarch: python-virtualenv-15.1.0-4.el7_7.noarch.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: python-virtualenv-15.1.0-4.el7_7.src.rpm noarch: python-virtualenv-15.1.0-4.el7_7.noarch.rpm Red Hat Enterprise Linux Server (v. 7): Source: python-virtualenv-15.1.0-4.el7_7.src.rpm noarch: python-virtualenv-15.1.0-4.el7_7.noarch.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: python-virtualenv-15.1.0-4.el7_7.src.rpm noarch: python-virtualenv-15.1.0-4.el7_7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-18074 https://access.redhat.com/security/cve/CVE-2018-20060 https://access.redhat.com/security/cve/CVE-2019-11236 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXnD4v9zjgjWX9erEAQjmFg/9F5BMr4O5FpCZmfbn/f1essBhQmRlo19D 6KDKgg7K8uVRTlaVk/P5EbHGYKhyud1do6VbUd51lbscKP3JyNvmoTtB0UtPL9SS l78obtd45KI4pIDP457luxhxanXsDyQkuyCb3lmp3NiRoTOSlZz1rzzr4xdxgrDq S2MF16xLwUAbhVD1Ug3IrQuVNcartR7TCMrRYXpfRfpOkmcNkJZ2OIAFMWc1qf81 J1t/QalUWMFI1YlF5dBoBCmZse3ke7V01Q2kMikLQzmdr43sW7SZ47mZIiqP1YQ2 hboTWd/Lph3asYdH50jz9moYDK18RmPzEBG7UIQJxwPm7lzjEbFD4hWm8H9dN+OC k5hxo9Q+7udDLp+Z6RigqasKuwMYuz29hlq+ZQi2A3mVR36V76QpqIFwfLeEa22+ iJ4hYivrXkw4svz2zhjSL2iMVuzTPpwU8pYLqIlDuvRvru/UkVFUZQFAy9bglxLV LbIRuJC4j2zSMwy9epdcm7PTk8m9EF5ZjbWyXCPeuk6vgMpKgIHNj1knAwQa5Sju v970rReEgFvXiXDTR8rxWDuJVr2NOySi8tIXIER+E7F6o5sgK8mIi+1Y8KplpEb0 0SBPiRyz+f9qfq+nz6K1Q4esPUe7l1BX4Ha6I8GrB2KJrqj0x7latX1blTpY5dtq Tsgt8YVM57A=6Jbd -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for python-urllib3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2370-1 Rating: moderate References: #1119376 #1129071 #1132663 #1132900 Cross-References: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 CVE-2019-9740 Affected Products: SUSE Manager Server 3.2 SUSE Linux Enterprise Module for Public Cloud 12 SUSE Enterprise Storage 5 SUSE Enterprise Storage 4 SUSE CaaS Platform 3.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for python-urllib3 fixes the following issues: Security issues fixed: - CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071). - CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900). - CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663). - CVE-2018-20060: Remove Authorization header when redirecting cross-host (bsc#1119376). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 3.2: zypper in -t patch SUSE-SUSE-Manager-Server-3.2-2019-2370=1 - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2019-2370=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2019-2370=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2370=1 - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let youthen trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 3.2 (noarch): python-urllib3-1.22-3.14.1 - SUSE Linux Enterprise Module for Public Cloud 12 (noarch): python-urllib3-1.22-3.14.1 python3-urllib3-1.22-3.14.1 - SUSE Enterprise Storage 5 (noarch): python-urllib3-1.22-3.14.1 - SUSE Enterprise Storage 4 (noarch): python-urllib3-1.22-3.14.1 - SUSE CaaS Platform 3.0 (noarch): python-urllib3-1.22-3.14.1 References: https://www.suse.com/security/cve/CVE-2018-20060.html https://www.suse.com/security/cve/CVE-2019-11236.html https://www.suse.com/security/cve/CVE-2019-11324.html https://www.suse.com/security/cve/CVE-2019-9740.html https://bugzilla.suse.com/1119376 https://bugzilla.suse.com/1129071 https://bugzilla.suse.com/1132663 https://bugzilla.suse.com/1132900 _______________________________________________ sle-security-updates mailing list
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for python-urllib3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2331-1 Rating: moderate References: #1119376 #1129071 #1132663 #1132900 Cross-References: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 CVE-2019-9740 Affected Products: SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for python-urllib3 fixes the following issues: Security issues fixed: - CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071). - CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900). - CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663). - CVE-2018-20060: Remove Authorization header when redirecting cross-host (bsc#1119376). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-2331=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (noarch): python2-urllib3-1.22-6.4.1 python3-urllib3-1.22-6.4.1 References: https://www.suse.com/security/cve/CVE-2018-20060.html https://www.suse.com/security/cve/CVE-2019-11236.html https://www.suse.com/security/cve/CVE-2019-11324.html https://www.suse.com/security/cve/CVE-2019-9740.html https://bugzilla.suse.com/1119376 https://bugzilla.suse.com/1129071 https://bugzilla.suse.com/1132663 https://bugzilla.suse.com/1132900 _______________________________________________ sle-security-updates mailinglist
- Fix an issue similar to CVE-2018-20060 where the authorization header was removed only when the case matched. - Fix an issue where the system CA bundle was loaded even when an alternate bundle was explicitly specified (https://www.openwall.com/lists/oss-security/2019/04/17/3 Full changelog at: https://github.com/urllib3/urllib3/blob/1.24.2/CHANGES.rst. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-6afaa38e7b 2019-04-27 21:22:10.074071 --------------------------------------------------------------------------------Name : python-urllib3 Product : Fedora 30 Version : 1.24.2 Release : 1.fc30 URL : https://github.com/urllib3/urllib3 Summary : Python HTTP library with thread-safe connection pooling and file post Description : Python HTTP module with connection pooling and file POST abilities. --------------------------------------------------------------------------------Update Information: - Fix an issue similar to CVE-2018-20060 where the authorization header was removed only when the case matched. - Fix an issue where the system CA bundle was loaded even when an alternate bundle was explicitly specified (https://www.openwall.com/lists/oss-security/2019/04/17/3 Full changelog at: https://github.com/urllib3/urllib3/blob/1.24.2/CHANGES.rst --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1701014 - python-urllib3-1.24.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1701014 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-6afaa38e7b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.