MGASA-2019-0148
Dashboard / Vulnerabilities / MGASA-2019-0148
Summary: Updated python packages fix security vulnerability
Details: A vulnerability was found in Python 2.x through 2.7.16. An improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization could lead to an Information Disclosure (credentials, cookies, etc. that are cached against a given hostname) in the urllib.parse.urlsplit, urllib.parse.urlparse components. A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly (CVE-2019-9636).
References: https://advisories.mageia.org/MGASA-2019-0148.html, https://bugs.mageia.org/show_bug.cgi?id=24640, https://access.redhat.com/errata/RHSA-2019:0710
Affected packages
Package
Name: python
Purl: pkg:rpm/mageia/python?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
