Debian Package Tracker
Register | Log in
Subscribe

python-urllib3

HTTP library with thread-safe connection pooling for Python3

Choose email to subscribe with

general
  • source: python-urllib3 (main)
  • version: 1.26.2-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.5.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.9.1-3
  • o-o-sec: 1.9.1-3+deb8u1
  • oldstable: 1.19.1-1
  • old-bpo: 1.24.1-1~bpo9+1
  • stable: 1.24.1-1
  • testing: 1.26.2-1
  • unstable: 1.26.2-1
versioned links
  • 1.9.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9.1-3+deb8u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.19.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.24.1-1~bpo9+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.24.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.26.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-urllib3
action needed
lintian reports 2 errors high
Lintian reports 2 errors about this package. You should make the package lintian clean getting rid of them.
Created: 2020-10-22 Last update: 2020-10-22 04:34
4 ignored security issues in stretch low
There are 4 open security issues in stretch.
4 issues skipped by the security teams:
  • CVE-2018-20060: urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
  • CVE-2019-11236: In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
  • CVE-2019-11324: The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
  • CVE-2020-26137: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Please fix them.
Created: 2018-12-12 Last update: 2021-01-06 08:05
3 ignored security issues in buster low
There are 3 open security issues in buster.
3 issues skipped by the security teams:
  • CVE-2019-11236: In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
  • CVE-2019-11324: The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
  • CVE-2020-26137: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Please fix them.
Created: 2019-03-13 Last update: 2021-01-06 08:05
news
[rss feed]
  • [2021-01-06] python-urllib3 1.26.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-31] Accepted python-urllib3 1.26.2-1 (source) into unstable (Daniele Tricoli)
  • [2020-11-19] python-urllib3 1.25.11-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-14] Accepted python-urllib3 1.25.11-1 (source) into unstable (Dmitry Shachnev)
  • [2020-05-08] python-urllib3 1.25.9-1 MIGRATED to testing (Debian testing watch)
  • [2020-05-02] Accepted python-urllib3 1.25.9-1 (source) into unstable (Scott Kitterman) (signed by: Donald Scott Kitterman)
  • [2020-04-08] python-urllib3 1.25.8-2 MIGRATED to testing (Debian testing watch)
  • [2020-04-01] Accepted python-urllib3 1.25.8-2 (source) into unstable (Sandro Tosi)
  • [2020-02-17] python-urllib3 1.25.8-1 MIGRATED to testing (Debian testing watch)
  • [2020-02-11] Accepted python-urllib3 1.25.8-1 (source) into unstable (Håvard Flaget Aasen) (signed by: Utkarsh Gupta)
  • [2020-01-15] python-urllib3 1.25.6-5 MIGRATED to testing (Debian testing watch)
  • [2020-01-10] Accepted python-urllib3 1.25.6-5 (source) into unstable (Sandro Tosi)
  • [2019-12-10] python-urllib3 1.25.6-4 MIGRATED to testing (Debian testing watch)
  • [2019-12-05] Accepted python-urllib3 1.25.6-4 (source) into unstable (Daniele Tricoli)
  • [2019-12-02] Accepted python-urllib3 1.25.6-3 (source) into experimental (Daniele Tricoli)
  • [2019-10-27] Accepted python-urllib3 1.25.6-2 (source) into experimental (Daniele Tricoli)
  • [2019-10-12] Accepted python-urllib3 1.25.6-1 (source) into experimental (Drew Parsons)
  • [2019-06-20] Accepted python-urllib3 1.9.1-3+deb8u1 (source all) into oldstable (Roberto C. Sanchez)
  • [2019-03-31] Accepted python-urllib3 1.24.1-1~bpo9+1 (source) into stretch-backports->backports-policy, stretch-backports (Mattia Rizzolo)
  • [2019-02-21] python-urllib3 1.24.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-11] Accepted python-urllib3 1.24.1-1 (source all) into unstable (Daniele Tricoli)
  • [2019-01-10] Accepted python-urllib3 1.24.1-1~exp1 (source all) into experimental (Daniele Tricoli)
  • [2018-10-29] Accepted python-urllib3 1.24-1~bpo9+1 (source all) into stretch-backports, stretch-backports (Mattia Rizzolo)
  • [2018-10-29] python-urllib3 1.24-1 MIGRATED to testing (Debian testing watch)
  • [2018-10-25] Accepted python-urllib3 1.24-1 (source all) into unstable (Daniele Tricoli)
  • [2018-10-19] Accepted python-urllib3 1.24-1~exp1 (source all) into experimental (Daniele Tricoli) (signed by: Pierre-Elliott Bécue)
  • [2018-01-10] python-urllib3 1.22-1 MIGRATED to testing (Debian testing watch)
  • [2018-01-04] Accepted python-urllib3 1.22-1 (source) into unstable (Ondřej Nový)
  • [2017-08-09] python-urllib3 1.21.1-1 MIGRATED to testing (Debian testing watch)
  • [2017-08-03] Accepted python-urllib3 1.21.1-1 (source all) into unstable (Daniele Tricoli) (signed by: Piotr Ozarowski)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (2, 0)
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.25.11-1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing