Описание
Security update for python-urllib3
This update for python-urllib3 fixes the following issues:
- CVE-2020-26137: Fixed a CRLF injection via HTTP request method (bsc#1177120).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Список пакетов
openSUSE Leap 15.2
python2-urllib3-1.24-lp152.5.3.1
python2-urllib3-test-1.24-lp152.5.3.1
python3-urllib3-1.24-lp152.5.3.1
python3-urllib3-test-1.24-lp152.5.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:2237-1
- SUSE Security Ratings
- SUSE Bug 1177120
- SUSE CVE CVE-2020-26137 page
Описание
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Затронутые продукты
openSUSE Leap 15.2:python2-urllib3-1.24-lp152.5.3.1
openSUSE Leap 15.2:python2-urllib3-test-1.24-lp152.5.3.1
openSUSE Leap 15.2:python3-urllib3-1.24-lp152.5.3.1
openSUSE Leap 15.2:python3-urllib3-test-1.24-lp152.5.3.1
Ссылки
- CVE-2020-26137
- SUSE Bug 1177120
- SUSE Bug 1177211