Mandriva Linux Security Advisory : python-requests (MDVSA-2015:133)

Medium Nessus Plugin ID 82386


The remote Mandriva Linux host is missing one or more security updates.


Updated python-requests packages fix security vulnerabilities :

Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file (CVE-2014-1829).

It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected (CVE-2014-1830).

In python-requests before 2.6.0, a cookie without a host value set would use the hostname for the redirected URL exposing requests users to session fixation attacks and potentially cookie stealing (CVE-2015-2296).


Update the affected python-requests and / or python3-requests packages.

See Also

Plugin Details

Severity: Medium

ID: 82386

File Name: mandriva_MDVSA-2015-133.nasl

Version: $Revision: 1.1 $

Type: local

Published: 2015/03/30

Modified: 2015/03/30

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:python-requests, p-cpe:/a:mandriva:linux:python3-requests, cpe:/o:mandriva:business_server:2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2015/03/29

Reference Information

CVE: CVE-2014-1829, CVE-2014-1830, CVE-2015-2296

MDVSA: 2015:133