[Git][security-tracker-team/security-tracker][master] Add CVE-2020-7212/python-urllib3

Salvatore Bonaccorso carnil at debian.org
Sat Mar 7 07:20:13 GMT 2020



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d3558372 by Salvatore Bonaccorso at 2020-03-07T08:19:21+01:00
Add CVE-2020-7212/python-urllib3

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6682,8 +6682,15 @@ CVE-2020-7214
 	RESERVED
 CVE-2020-7213 (Parallels 13 uses cleartext HTTP as part of the update process, allowi ...)
 	NOT-FOR-US: Parallels
-CVE-2020-7212
+CVE-2020-7212 [denial of service (CPU consumption) because of inefficient algorithm in _encode_invalid_chars function]
 	RESERVED
+	- python-urllib3 <unfixed>
+	[buster] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+	[stretch] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+	[jessie] - python-urllib3 <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/urllib3/urllib3/pull/1787
+	NOTE: Introduced by: https://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221a (1.25.2)
+	NOTE: Fixed by: https://github.com/urllib3/urllib3/commit/a2697e7c6b275f05879b60f593c5854a816489f0 (1.25.8)
 CVE-2020-7211 (tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\  ...)
 	- libslirp <unfixed> (unimportant)
 	NOTE: https://bugs.launchpad.net/qemu/+bug/1812451



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d35583723f309a0255eb3b510a18e2c3ee1002f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d35583723f309a0255eb3b510a18e2c3ee1002f3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200307/3855c72f/attachment.html>


More information about the debian-security-tracker-commits mailing list