Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . MGASA-2020-0269 - Updated python-httplib2 packages fix security vulnerability Publication date: 04 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0269.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11078 Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping (CVE-2020-11078). References: - https://bugs.mageia.org/show_bug.cgi?id=26750 - https://lists.debian.org/debian-lts-announce/2020/06/msg00000.html - https://www.cve.org/CVERecord?id=CVE-2020-11078 SRPMS: - 7/core/python-httplib2-0.18.0-1.mga7 . The latest python-httplib2 updates address critical security issues related to header manipulation and concealed request vulnerabilities.. python-httplib2 Update, Mageia Security Advisory, Software Security Fix, Request Header Vulnerability. . LinuxSecurity.com Team
In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . Package : python-httplib2 Version : 0.9+dfsg-2+deb8u1 CVE ID : CVE-2020-11078 In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. For Debian 8 "Jessie", this problem has been fixed in version 0.9+dfsg-2+deb8u1. We recommend that you upgrade your python-httplib2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the python-httplib2 library to mitigate risks associated with URI exploitation by malicious entities, potentially resulting in unauthorized API calls.. Debian Security Update, python-httplib2, Vulnerability Prevention. . LinuxSecurity.com Team
httplib2 could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-1375-1 February 27, 2012 python-httplib2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: httplib2 could be made to expose sensitive information over the network. Software Description: - python-httplib2: comprehensive HTTP client library written for Python Details: The httplib2 Python library earlier than version 0.7.0 did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information in applications that used the httplib2 library. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: python-httplib2 0.7.2-1ubuntu2~0.11.10.1 python3-httplib2 0.7.2-1ubuntu2~0.11.10.1 Ubuntu 11.04: python-httplib2 0.7.2-1ubuntu2~0.11.04.1 python3-httplib2 0.7.2-1ubuntu2~0.11.04.1 Ubuntu 10.10: python-httplib2 0.7.2-1ubuntu2~0.10.10.1 python3-httplib2 0.7.2-1ubuntu2~0.10.10.1 Ubuntu 10.04 LTS: python-httplib2 0.7.2-1ubuntu2~0.10.04.1 In general, a standard system update will make all the necessary changes. This update uses a new upstream release, which includes additional bug fixes. References: https://ubuntu.com/security/notices/USN-1375-1 https://bugs.launchpad.net/ubuntu/+source/python-httplib2/+bug/882030 Package Information: https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.11.10.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.11.04.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.10.10.1 https://launchpad.net/ubuntu/+source/python-httplib2/0.7.2-1ubuntu2~0.10.04.1 . Ubuntu Security Notice USN-1375-1 highlights a vulnerability in httplib2 that may lead to sensitive information exposure. Users should update promptly. python-httplib2,data security,network threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.