MGASA-2014-0409

Source
https://advisories.mageia.org/MGASA-2014-0409.html
Import Source
https://advisories.mageia.org/MGASA-2014-0409.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0409
Related
Published
2014-10-09T14:39:32Z
Modified
2014-10-09T14:20:26Z
Summary
Updated python-requests packages fix security vulnerabilities
Details

Updated python-requests packages fix security vulnerability:

Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file (CVE-2014-1829).

It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected (CVE-2014-1830).

References
Credits

Affected packages

Mageia:4 / python-requests

Package

Name
python-requests
Purl
pkg:rpm/mageia/python-requests?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.0-1.mga4

Ecosystem specific

{
    "section": "core"
}