[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253741

 
 

909

 
 

197391

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2020-1340 --- python-pip python26-pip python27-pip python34-pip python35-pip python36-pip

ID: oval:org.secpod.oval:def:1601095Date: (C)2020-02-11   (M)2024-05-22
Class: PATCHFamily: unix




In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument

Platform:
Amazon Linux AMI
Product:
python-pip
python26-pip
python27-pip
python34-pip
python35-pip
python36-pip
Reference:
ALAS-2020-1340
CVE-2019-11236
CVE-2019-11324
CVE    2
CVE-2019-11236
CVE-2019-11324

© SecPod Technologies