MGASA-2014-0409
Dashboard / Vulnerabilities / MGASA-2014-0409
Summary: Updated python-requests packages fix security vulnerabilities
Details: Updated python-requests packages fix security vulnerability: Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file (CVE-2014-1829). It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected (CVE-2014-1830).
References: https://advisories.mageia.org/MGASA-2014-0409.html, https://bugs.mageia.org/show_bug.cgi?id=14130, https://bugzilla.redhat.com/show_bug.cgi?id=1046626, https://bugzilla.redhat.com/show_bug.cgi?id=1144907
Affected packages
Package
Name: python-requests
Purl: pkg:rpm/mageia/python-requests?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
