Debian Package Tracker
Register | Log in
Subscribe

python-httplib2

comprehensive HTTP client library written for Python3

Choose email to subscribe with

general
  • source: python-httplib2 (main)
  • version: 0.18.1-3
  • maintainer: Debian Python Team (DMD)
  • uploaders: Andrea Colangelo [DMD] – Chris Lamb [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.9.2+dfsg-1
  • stable: 0.11.3-2
  • testing: 0.18.1-3
  • unstable: 0.18.1-3
versioned links
  • 0.9.2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.18.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-httplib2
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:00:48
    Last run: 2020-05-18 17:41:56 UTC
    Previous status: fail

  • testing: pass (log)
    The tests ran in 0:00:42
    Last run: 2021-04-13 11:16:24 UTC
    Previous status: pass

  • stable: fail (log)
    The tests ran in 0:01:21
    Last run: 2021-01-22 10:51:27 UTC
    Previous status: fail

Created: 2019-02-14 Last update: 2021-04-18 15:06
A new upstream version is available: 0.19.1 high
A new upstream version 0.19.1 is available, you should consider packaging it.
Created: 2021-02-08 Last update: 2021-04-18 14:01
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2021-21240: httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library.
Created: 2021-02-19 Last update: 2021-03-21 19:04
2 security issues in buster high

There are 2 open security issues in buster.

1 important issue:
  • CVE-2021-21240: httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library.
1 issue left for the package maintainer to handle:
  • CVE-2020-11078: (needs triaging) In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. This has been fixed in 0.18.0.

You can find information about how to handle this issue in the security team's documentation.

Created: 2021-02-19 Last update: 2021-03-21 19:04
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2021-21240: httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library.
Created: 2021-02-19 Last update: 2021-03-21 19:04
news
[rss feed]
  • [2021-02-02] python-httplib2 0.18.1-3 MIGRATED to testing (Debian testing watch)
  • [2021-01-31] Accepted python-httplib2 0.18.1-3 (source) into unstable (Stefano Rivera)
  • [2021-01-31] Accepted python-httplib2 0.18.1-2 (source) into unstable (Stefano Rivera)
  • [2020-06-01] Accepted python-httplib2 0.9+dfsg-2+deb8u1 (source all) into oldoldstable (Abhijith PA)
  • [2020-05-30] python-httplib2 0.18.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-27] Accepted python-httplib2 0.18.1-1 (source) into unstable (Dimitri John Ledkov)
  • [2020-05-23] python-httplib2 0.17.4-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-20] Accepted python-httplib2 0.17.4-1 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2020-04-16] python-httplib2 0.14.0-3 MIGRATED to testing (Debian testing watch)
  • [2020-04-10] Accepted python-httplib2 0.14.0-3 (source) into unstable (Colin Watson)
  • [2020-04-03] python-httplib2 0.14.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-03-28] Accepted python-httplib2 0.14.0-2 (source) into unstable (Sandro Tosi)
  • [2020-01-13] python-httplib2 0.14.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-01-08] Accepted python-httplib2 0.14.0-1 (source) into unstable (Håvard Flaget Aasen) (signed by: Jonathan Carter)
  • [2019-02-24] python-httplib2 0.11.3-2 MIGRATED to testing (Debian testing watch)
  • [2019-02-13] Accepted python-httplib2 0.11.3-2 (source all) into unstable (Chris Lamb)
  • [2018-09-10] python-httplib2 0.11.3-1 MIGRATED to testing (Debian testing watch)
  • [2018-09-05] Accepted python-httplib2 0.11.3-1 (source) into unstable (ChangZhuo Chen (陳昌倬)) (signed by: ChangZhuo Chen)
  • [2016-11-15] python-httplib2 0.9.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2016-11-09] Accepted python-httplib2 0.9.2+dfsg-1 (source all) into unstable (Scott Kitterman) (signed by: Donald Scott Kitterman)
  • [2015-09-14] python-httplib2 0.9.1+dfsg-1 MIGRATED to testing (Britney)
  • [2015-09-08] Accepted python-httplib2 0.9.1+dfsg-1 (source) into unstable (Dmitry Shachnev)
  • [2014-10-04] python-httplib2 0.9+dfsg-2 MIGRATED to testing (Britney)
  • [2014-09-28] Accepted python-httplib2 0.9+dfsg-2 (source all) into unstable (Andrea Colangelo)
  • [2014-05-04] python-httplib2 0.9+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2014-04-28] Accepted python-httplib2 0.9+dfsg-1 (source all) (Luca Falavigna)
  • [2013-08-27] python-httplib2 0.8-2 MIGRATED to testing (Debian testing watch)
  • [2013-08-19] Accepted python-httplib2 0.7.4-2+deb7u1 (source all) (Vincent Bernat)
  • [2013-08-16] Accepted python-httplib2 0.8-2 (source all) (Vincent Bernat)
  • [2013-03-18] Accepted python-httplib2 0.8-1 (source all) (Luca Falavigna)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.18.1-3
  • 1 bug

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing