DSA-3146-1 requests -- security update

Related Vulnerabilities: CVE-2014-1829   CVE-2014-1830  

Jakub Wilk discovered that in requests, an HTTP library for the Python language, authentication information was improperly handled when a redirect occured. This would allow remote servers to obtain two different types of sensitive information: proxy passwords from the Proxy-Authorization header (CVE-2014-1830), or netrc passwords from the Authorization header (CVE-2014-1829). For the stable distribution (wheezy), this problem has been fixed in version 0.12.1-1+deb7u1. For the upcoming stable distribution (jessie) and unstable distribution (sid), this problem has been fixed in version 2.3.0-1. We recommend that you upgrade your requests packages.

Debian Security Advisory

DSA-3146-1 requests -- security update

Date Reported:
30 Jan 2015
Affected Packages:
requests
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 733108.
In Mitre's CVE dictionary: CVE-2014-1829, CVE-2014-1830.
More information:

Jakub Wilk discovered that in requests, an HTTP library for the Python language, authentication information was improperly handled when a redirect occured. This would allow remote servers to obtain two different types of sensitive information: proxy passwords from the Proxy-Authorization header (CVE-2014-1830), or netrc passwords from the Authorization header (CVE-2014-1829).

For the stable distribution (wheezy), this problem has been fixed in version 0.12.1-1+deb7u1.

For the upcoming stable distribution (jessie) and unstable distribution (sid), this problem has been fixed in version 2.3.0-1.

We recommend that you upgrade your requests packages.