Debian Security Advisory

DLA-1828-1 python-urllib3 -- LTS security update

Date Reported:
20 Jun 2019
Affected Packages:
python-urllib3
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 927172.
In Mitre's CVE dictionary: CVE-2019-11236.
More information:

A vulnerability was discovered in python-urllib3, an HTTP library with thread-safe connection pooling, whereby an attacker can inject CRLF characters in the request parameter.

For Debian 8 Jessie, this problem has been fixed in version 1.9.1-3+deb8u1.

We recommend that you upgrade your python-urllib3 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS