Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in incorrect certificate validation, CRLF injection or man-in-the-middle attacks. For the stable distribution (trixie), these problems have been fixed in version 21.0.10+7-1~deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6112-1
The container suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update:. SUSE Image Update Advisory: suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2021:410-1 Image Tags : suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64:20210304 Image Release : Severity : moderate Type : security References : 1177211 1177460 1180603 1181571 CVE-2020-26116 ----------------------------------------------------------------- The container suse-sles-15-chost-byos-v20210304-hvm-ssd-x86_64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:293-1 Released: Wed Feb 3 12:52:34 2021 Summary: Recommended update for gmp Type: recommended Severity: moderate References: 1180603 This update for gmp fixes the following issues: - correct license statements of packages (library itself is no GPL-3.0) (bsc#1180603) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:301-1 Released: Thu Feb 4 08:46:27 2021 Summary: Recommended update for timezone Type: recommended Severity: moderate References: 1177460 This update for timezone fixes the following issues: - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. ----------------------------------------------------------------- Advisory ID: SUSE-OU-2021:339-1 Released: Mon Feb 8 13:16:07 2021 Summary: Optional update for pam Type: optional Severity: low References: This update for pam fixes the following issues: - Added rpm macros for this package, so that other packages can make use of it This patch is optional to be installed - it doesn't fix anybugs. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:341-1 Released: Mon Feb 8 17:39:53 2021 Summary: Security update for python-urllib3 Type: security Severity: moderate References: 1177211,1181571,CVE-2020-26116 This update for python-urllib3 fixes the following issues: - CVE-2020-26116: Raise ValueError if method contains control characters and thus prevent CRLF injection into URLs (bsc#1177211). - Skip test for RECENT_DATE (bsc#1181571). . Essential Security Patch Released For SUSE Container Fixing CRLF Exploits. Ensure Your Safety!. SUSE Security Update, Python Urllib3, Container Security. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-urllib3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0515-1 Rating: moderate References: #1177211 Cross-References: CVE-2020-26116 CVSS scores: CVE-2020-26116 (NVD) : 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVE-2020-26116 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-urllib3 fixes the following issues: - CVE-2020-26116: Raise ValueError if method contains control characters and thus prevent CRLF injection into URLs (bsc#1177211). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-515=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-515=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-515=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): python-urllib3-1.22-5.15.1 - SUSE OpenStack Cloud 8 (noarch): python-urllib3-1.22-5.15.1 - HPE Helion Openstack 8 (noarch): python-urllib3-1.22-5.15.1 References: https://www.suse.com/security/cve/CVE-2020-26116.html https://bugzilla.suse.com/1177211 . SUSE Security Update for python-requests addresses a vulnerability related to improper input handling that could lead to contentinjection in network requests. Find out more inside.. SUSE Python Urllib3 Update Control Character. . LinuxSecurity.com Team
CVE-2020-26116: HTTP request method CRLF injection in httplib. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-887d3fa26f 2020-10-16 15:18:47.312170 --------------------------------------------------------------------------------Name : python27 Product : Fedora 32 Version : 2.7.18 Release : 6.fc32 URL : https://www.python.org/ Summary : Version 2.7 of the Python interpreter Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that Python 2 is not supported upstream after 2020-01-01, please use the python3 package instead if you can. This package also provides the "python2" executable. --------------------------------------------------------------------------------Update Information: CVE-2020-26116: HTTP request method CRLF injection in httplib --------------------------------------------------------------------------------ChangeLog: * Wed Sep 30 2020 Petr Viktorin - 2.7.18-6 - CVE-2020-26116: Reject control chars in HTTP method in httplib.putrequest * Tue Sep 29 2020 Petr Viktorin - 2.7.18-5 - Import patches from GitHub tree --------------------------------------------------------------------------------References: [ 1 ] Bug #1883244 - CVE-2020-26116 python27: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1883244 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-887d3fa26f' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Tim Düsterhus discovered that haproxy, a TCP/HTTP reverse proxy, did not properly sanitize HTTP headers when converting from HTTP/2 to HTTP/1. This would allow a remote user to perform CRLF injections. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4577-1
It was discovered that urllib3 incorrectly removed Authorization HTTP headers when handled cross-origin redirects. This could result in credentials being sent to unintended hosts (CVE-2018-20060). It was discovered that urllib3 incorrectly stripped certain characters . MGASA-2019-0258 - Updated python-urllib3 packages fix security vulnerability Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0258.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-20060, CVE-2019-11236, CVE-2019-11324 It was discovered that urllib3 incorrectly removed Authorization HTTP headers when handled cross-origin redirects. This could result in credentials being sent to unintended hosts (CVE-2018-20060). It was discovered that urllib3 incorrectly stripped certain charactersfrom requests. A remote attacker could use this issue to perform CRLF injection (CVE-2019-11236). It was discovered that urllib3 incorrectly handled situations where a desired set of CA certificates were specified. This could result in certificates being accepted by the default CA certificates contrary to expectatons (CVE-2019-11324). The python-urllib3 package has been updated to version 1.24.3 to fix these issues and other bugs. The python-requests package has been fixed to work with the updated python-urllib3 References: - https://bugs.mageia.org/show_bug.cgi?id=23880 - https://ubuntu.com/security/notices/USN-3990-1 - https://www.cve.org/CVERecord?id=CVE-2018-20060 - https://www.cve.org/CVERecord?id=CVE-2019-11236 - https://www.cve.org/CVERecord?id=CVE-2019-11324 SRPMS: - 6/core/python-requests-2.11.1-2.2.mga6 - 6/core/python-urllib3-1.24.3-1.mga6 . Recent updates to the python-urllib3 library address critical security vulnerabilities that could lead to unauthorized access and code injection risks.. python-urllib3, security update, authorization headers, cross-origin. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a CRLF injection attack in the Go programming language runtime library. Passing \r\n to http.NewRequest could allow execution of arbitrary . Package : golang Version : 2:1.3.3-1+deb8u2 CVE ID : CVE-2019-9741 Debian Bug : #924630 It was discovered that there was a CRLF injection attack in the Go programming language runtime library. Passing \r\n to http.NewRequest could allow execution of arbitrary HTTP headers or Redis commands. For Debian 8 "Jessie", this issue has been fixed in golang version 2:1.3.3-1+deb8u2. We recommend that you upgrade your golang packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-22f1a8404e 2017-06-02 17:35:06.904003 --------------------------------------------------------------------------------Name : wget Product : Fedora 25 Version : 1.18 Release : 3.fc25 URL : Summary : A utility for retrieving files using the HTTP or FTP protocols Description : GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability. --------------------------------------------------------------------------------Update Information: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c --------------------------------------------------------------------------------References: [ 1 ] Bug #1429984 - CVE-2017-6508 wget: CRLF injection in the url_parse function in url.c https://bugzilla.redhat.com/show_bug.cgi?id=1429984 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade wget' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.