USN-3990-2: urllib3 vulnerability
USN-3990-1 fixed a vulnerability in urllib3. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that urllib3 incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. (CVE-2019-11236)
Affected Software
Event History
Frequently Asked Questions
What vulnerability does USN-3990-2 address?
USN-3990-2 addresses a vulnerability in urllib3 that allows for CRLF injection.
What is the severity of USN-3990-2?
The severity of USN-3990-2 is not specified in the provided information.
Which software is affected by USN-3990-2?
USN-3990-2 affects Ubuntu 14.04 ESM and the python-urllib3 and python3-urllib3 packages.
How do I fix USN-3990-2?
To fix USN-3990-2, update the python-urllib3 and python3-urllib3 packages to version 1.7.1-1ubuntu4.1+esm1 or later.
Where can I find more information about USN-3990-2?
More information about USN-3990-2 can be found at the following references: [CVE-2019-11236](https://ubuntu.com/security/CVE-2019-11236), [USN-3990-1](https://ubuntu.com/security/notices/USN-3990-1), [Launchpad](https://launchpad.net/ubuntu/+source/python-urllib3/1.7.1-1ubuntu4.1+esm1).