[Git][security-tracker-team/security-tracker][master] Fix sid version for CVE-2018-25091/python-urllib3.

Guilhem Moulin (@guilhem) guilhem at debian.org
Mon Oct 16 00:10:47 BST 2023



Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker


Commits:
16b2d4ed by Guilhem Moulin at 2023-10-16T01:10:02+02:00
Fix sid version for CVE-2018-25091/python-urllib3.

The first version ≥1.25.2 that landed in unstable is 1.25.6-4 no
1.25.6-1 (which was uploaded to experimental only).

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2,10 +2,10 @@ CVE-2023-38312 (A directory traversal vulnerability in Valve Counter-Strike 8684
 	TODO: check
 CVE-2018-25091 (urllib3 before 1.24.2 does not remove the authorization HTTP header wh ...)
 	{DLA-3610-1}
-	- python-urllib3 1.25.6-1
+	- python-urllib3 1.25.6-4
 	NOTE: https://github.com/urllib3/urllib3/issues/1510
 	NOTE: This issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
-	NOTE: Fixed by https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.24.2)
+	NOTE: Fixed by https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc (1.25)
 CVE-2023-5586 (NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0 ...)
 	TODO: check
 CVE-2023-5585 (A vulnerability was found in SourceCodester Online Motorcycle Rental S ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16b2d4ed19004e39e5ac274364d1377089712b45

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/16b2d4ed19004e39e5ac274364d1377089712b45
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231015/4ba61236/attachment.htm>


More information about the debian-security-tracker-commits mailing list