Mandriva Linux Security Advisory : python-requests (MDVSA-2015:133)

medium Nessus Plugin ID 82386

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Updated python-requests packages fix security vulnerabilities :

Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file (CVE-2014-1829).

It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected (CVE-2014-1830).

In python-requests before 2.6.0, a cookie without a host value set would use the hostname for the redirected URL exposing requests users to session fixation attacks and potentially cookie stealing (CVE-2015-2296).

Solution

Update the affected python-requests and / or python3-requests packages.

See Also

http://advisories.mageia.org/MGASA-2014-0409.html

http://advisories.mageia.org/MGASA-2015-0120.html

Plugin Details

Severity: Medium

ID: 82386

File Name: mandriva_MDVSA-2015-133.nasl

Version: 1.4

Type: local

Published: 3/30/2015

Updated: 1/14/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:python3-requests, cpe:/o:mandriva:business_server:2, p-cpe:/a:mandriva:linux:python-requests

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 3/29/2015

Reference Information

CVE: CVE-2014-1829, CVE-2014-1830, CVE-2015-2296

MDVSA: 2015:133