First published: Mon Jul 29 2019(Updated: )
USN-3990-1 fixed a vulnerability in urllib3. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that urllib3 incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. (CVE-2019-11236)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python-urllib3 | <1.7.1-1ubuntu4.1+esm1 | 1.7.1-1ubuntu4.1+esm1 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/python3-urllib3 | <1.7.1-1ubuntu4.1+esm1 | 1.7.1-1ubuntu4.1+esm1 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3990-2 addresses a vulnerability in urllib3 that allows for CRLF injection.
The severity of USN-3990-2 is not specified in the provided information.
USN-3990-2 affects Ubuntu 14.04 ESM and the python-urllib3 and python3-urllib3 packages.
To fix USN-3990-2, update the python-urllib3 and python3-urllib3 packages to version 1.7.1-1ubuntu4.1+esm1 or later.
More information about USN-3990-2 can be found at the following references: [CVE-2019-11236](https://ubuntu.com/security/CVE-2019-11236), [USN-3990-1](https://ubuntu.com/security/notices/USN-3990-1), [Launchpad](https://launchpad.net/ubuntu/+source/python-urllib3/1.7.1-1ubuntu4.1+esm1).