Bug 19667 - python-urllib3 new security issue CVE-2016-9015
Summary: python-urllib3 new security issue CVE-2016-9015
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Philippe Makowski
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-27 14:16 CEST by David Walser
Modified: 2016-11-02 20:47 CET (History)
0 users

See Also:
Source RPM: python-urllib3-1.17-2.mga6.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-10-27 14:16:15 CEST
A security issue fixed upstream in python-urllib3 has been announced:
http://openwall.com/lists/oss-security/2016/10/27/6

The issue is fixed upstream in 1.18.1.

Mageia 5 is not affected.

Technically we are not affected either from what I understand, as we don't use OpenSSL 1.1, but we should probably fix this anyway.
Comment 1 Philippe Makowski 2016-11-02 14:46:56 CET
freeze push asked
Comment 2 David Walser 2016-11-02 20:47:44 CET
python-urllib3-1.18.1-1.mga6 uploaded for Cauldron.  Thanks Philippe!

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.