Debian Security Advisory
DLA-1828-1 python-urllib3 -- LTS security update
- Date Reported:
- 20 Jun 2019
- Affected Packages:
- python-urllib3
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 927172.
In Mitre's CVE dictionary: CVE-2019-11236. - More information:
-
A vulnerability was discovered in python-urllib3, an HTTP library with thread-safe connection pooling, whereby an attacker can inject CRLF characters in the request parameter.
For Debian 8
Jessie
, this problem has been fixed in version 1.9.1-3+deb8u1.We recommend that you upgrade your python-urllib3 packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS