Debian Package Tracker
Register | Log in
Subscribe

python-urllib3

HTTP library with thread-safe connection pooling for Python3

Choose email to subscribe with

general
  • source: python-urllib3 (main)
  • version: 1.26.9-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.19.1-1
  • o-o-sec: 1.19.1-1+deb9u1
  • o-o-bpo: 1.24.1-1~bpo9+1
  • oldstable: 1.24.1-1
  • stable: 1.26.5-1~exp1
  • testing: 1.26.9-1
  • unstable: 1.26.9-1
versioned links
  • 1.19.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.19.1-1+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.24.1-1~bpo9+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.24.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.5-1~exp1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-urllib3
action needed
4 low-priority security issues in buster low

There are 4 open security issues in buster.

4 issues left for the package maintainer to handle:
  • CVE-2019-11236: (needs triaging) In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
  • CVE-2019-11324: (needs triaging) The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
  • CVE-2020-26137: (needs triaging) urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
  • CVE-2021-33503: (needs triaging) An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-03-21 18:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.6.0).
Created: 2022-05-11 Last update: 2022-05-11 23:24
news
[rss feed]
  • [2022-03-22] python-urllib3 1.26.9-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-19] Accepted python-urllib3 1.26.9-1 (source) into unstable (Daniele Tricoli)
  • [2022-03-16] python-urllib3 1.26.8-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-14] Accepted python-urllib3 1.26.8-1 (source) into unstable (Daniele Tricoli)
  • [2021-07-08] python-urllib3 1.26.5-1~exp1 MIGRATED to testing (Debian testing watch)
  • [2021-06-27] Accepted python-urllib3 1.26.5-1~exp1 (source) into unstable (Daniele Tricoli)
  • [2021-06-15] Accepted python-urllib3 1.19.1-1+deb9u1 (source all) into oldstable (Abhijith PA)
  • [2021-05-17] python-urllib3 1.26.4-1 MIGRATED to testing (Debian testing watch)
  • [2021-05-12] Accepted python-urllib3 1.26.4-1 (source) into unstable (Stefano Rivera)
  • [2021-01-06] python-urllib3 1.26.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted python-urllib3 1.26.2-1 (source) into unstable (Daniele Tricoli)
  • [2020-11-19] python-urllib3 1.25.11-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-14] Accepted python-urllib3 1.25.11-1 (source) into unstable (Dmitry Shachnev)
  • [2020-05-08] python-urllib3 1.25.9-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-02] Accepted python-urllib3 1.25.9-1 (source) into unstable (Scott Kitterman) (signed by: Donald Scott Kitterman)
  • [2020-04-08] python-urllib3 1.25.8-2 MIGRATED to testing (Debian testing watch)
  • [2020-04-01] Accepted python-urllib3 1.25.8-2 (source) into unstable (Sandro Tosi)
  • [2020-02-17] python-urllib3 1.25.8-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-11] Accepted python-urllib3 1.25.8-1 (source) into unstable (Håvard Flaget Aasen) (signed by: Utkarsh Gupta)
  • [2020-01-15] python-urllib3 1.25.6-5 MIGRATED to testing (Debian testing watch)
  • [2020-01-10] Accepted python-urllib3 1.25.6-5 (source) into unstable (Sandro Tosi)
  • [2019-12-10] python-urllib3 1.25.6-4 MIGRATED to testing (Debian testing watch)
  • [2019-12-05] Accepted python-urllib3 1.25.6-4 (source) into unstable (Daniele Tricoli)
  • [2019-12-02] Accepted python-urllib3 1.25.6-3 (source) into experimental (Daniele Tricoli)
  • [2019-10-27] Accepted python-urllib3 1.25.6-2 (source) into experimental (Daniele Tricoli)
  • [2019-10-12] Accepted python-urllib3 1.25.6-1 (source) into experimental (Drew Parsons)
  • [2019-06-20] Accepted python-urllib3 1.9.1-3+deb8u1 (source all) into oldstable (Roberto C. Sanchez)
  • [2019-03-31] Accepted python-urllib3 1.24.1-1~bpo9+1 (source) into stretch-backports->backports-policy, stretch-backports (Mattia Rizzolo)
  • [2019-02-21] python-urllib3 1.24.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-11] Accepted python-urllib3 1.24.1-1 (source all) into unstable (Daniele Tricoli)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.26.9-1
  • 1 bug

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing