Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia: 2020-0269 Moderate: httplib2 Request Header Manipulation

Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . MGASA-2020-0269 - Updated python-httplib2 packages fix security vulnerability Publication date: 04 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0269.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11078 Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping (CVE-2020-11078). References: - https://bugs.mageia.org/show_bug.cgi?id=26750 - https://lists.debian.org/debian-lts-announce/2020/06/msg00000.html - https://www.cve.org/CVERecord?id=CVE-2020-11078 SRPMS: - 7/core/python-httplib2-0.18.0-1.mga7 . The latest python-httplib2 updates address critical security issues related to header manipulation and concealed request vulnerabilities.. python-httplib2 Update, Mageia Security Advisory, Software Security Fix, Request Header Vulnerability. . LinuxSecurity.com Team

Calendar 2 Jul 04, 2020 Mageia
197

Debian: DLA-2232-1 Moderate: python-httplib2 Request Manipulation

In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . Package : python-httplib2 Version : 0.9+dfsg-2+deb8u1 CVE ID : CVE-2020-11078 In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. For Debian 8 "Jessie", this problem has been fixed in version 0.9+dfsg-2+deb8u1. We recommend that you upgrade your python-httplib2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the python-httplib2 library to mitigate risks associated with URI exploitation by malicious entities, potentially resulting in unauthorized API calls.. Debian Security Update, python-httplib2, Vulnerability Prevention. . LinuxSecurity.com Team

Calendar 2 Jun 01, 2020 Debian LTS
172

Ubuntu 11.10 USN-1375-1 Moderate: httplib2 Sensitivity Threat

httplib2 could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-1375-1 February 27, 2012 python-httplib2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: httplib2 could be made to expose sensitive information over the network. Software Description: - python-httplib2: comprehensive HTTP client library written for Python Details: The httplib2 Python library earlier than version 0.7.0 did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information in applications that used the httplib2 library. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: python-httplib2 0.7.2-1ubuntu2~0.11.10.1 python3-httplib2 0.7.2-1ubuntu2~0.11.10.1 Ubuntu 11.04: python-httplib2 0.7.2-1ubuntu2~0.11.04.1 python3-httplib2 0.7.2-1ubuntu2~0.11.04.1 Ubuntu 10.10: python-httplib2 0.7.2-1ubuntu2~0.10.10.1 python3-httplib2 0.7.2-1ubuntu2~0.10.10.1 Ubuntu 10.04 LTS: python-httplib2 0.7.2-1ubuntu2~0.10.04.1 In general, a standard system update will make all the necessary changes. This update uses a new upstream release, which includes additional bug fixes. References: https://ubuntu.com/security/notices/USN-1375-1 https://bugs.launchpad.net/ubuntu/+source/python-httplib2/+bug/882030 Package Information: https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.11.10.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.11.04.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.10.10.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.10.04.1 . Ubuntu Security Notice USN-1375-1 highlights a vulnerability in httplib2 that may lead to sensitive information exposure. Users should update promptly. python-httplib2,data security,network threats. . LinuxSecurity.com Team

Calendar 2 Feb 27, 2012 Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here