Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts . MGASA-2020-0269 - Updated python-httplib2 packages fix security vulnerability Publication date: 04 Jul 2020 URL: https://advisories.mageia.org/MGASA-2020-0269.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11078 Updated python-httplib2 packages fix security vulnerability: In httplib2, an attacker controlling unescaped part of uri for httplib2.Http.request() could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping (CVE-2020-11078). References: - https://bugs.mageia.org/show_bug.cgi?id=26750 - https://lists.debian.org/debian-lts-announce/2020/06/msg00000.html - https://www.cve.org/CVERecord?id=CVE-2020-11078 SRPMS: - 7/core/python-httplib2-0.18.0-1.mga7 . The latest python-httplib2 updates address critical security issues related to header manipulation and concealed request vulnerabilities.. python-httplib2 Update, Mageia Security Advisory, Software Security Fix, Request Header Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.