openSUSE Security Update: Security update for python-urllib3
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:2133-1
Rating: moderate
References: #1129071 #1132663 #1132900
Cross-References: CVE-2019-11236 CVE-2019-11324 CVE-2019-9740
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for python-urllib3 fixes the following issues:
Security issues fixed:
– CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071).
– CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900).
– CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.
Alternatively you can run the command listed for your product:
– openSUSE Leap 15.1:
zypper in -t patch openSUSE-2019-2133=1
Package List:
– openSUSE Leap 15.1 (noarch):
python2-urllib3-1.24-lp151.2.3.1
python2-urllib3-test-1.24-lp151.2.3.1
python3-urllib3-1.24-lp151.2.3.1
python3-urllib3-test-1.24-lp151.2.3.1
References:
https://www.suse.com/security/cve/CVE-2019-11236.html
https://www.suse.com/security/cve/CVE-2019-11324.html
https://www.suse.com/security/cve/CVE-2019-9740.html
https://bugzilla.suse.com/1129071
https://bugzilla.suse.com/1132663
https://bugzilla.suse.com/1132900
—
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
openSUSE Security Update: Security update for python-urllib3
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:2131-1
Rating: moderate
References: #1119376 #1129071 #1132663 #1132900
Cross-References: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324
CVE-2019-9740
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that fixes four vulnerabilities is now available.
Description:
This update for python-urllib3 fixes the following issues:
Security issues fixed:
– CVE-2019-9740: Fixed CRLF injection issue (bsc#1129071).
– CVE-2019-11324: Fixed invalid CA certificat verification (bsc#1132900).
– CVE-2019-11236: Fixed CRLF injection via request parameter (bsc#1132663).
– CVE-2018-20060: Remove Authorization header when redirecting cross-host
(bsc#1119376).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.
Alternatively you can run the command listed for your product:
– openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-2131=1
Package List:
– openSUSE Leap 15.0 (noarch):
python2-urllib3-1.22-lp150.5.3.1
python3-urllib3-1.22-lp150.5.3.1
References:
https://www.suse.com/security/cve/CVE-2018-20060.html
https://www.suse.com/security/cve/CVE-2019-11236.html
https://www.suse.com/security/cve/CVE-2019-11324.html
https://www.suse.com/security/cve/CVE-2019-9740.html
https://bugzilla.suse.com/1119376
https://bugzilla.suse.com/1129071
https://bugzilla.suse.com/1132663
https://bugzilla.suse.com/1132900
—
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org