Mandriva Linux Security Advisory : python-requests (MDVSA-2015:133)

Medium Nessus Plugin ID 82386

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 4.7

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

Updated python-requests packages fix security vulnerabilities :

Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file (CVE-2014-1829).

It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected (CVE-2014-1830).

In python-requests before 2.6.0, a cookie without a host value set would use the hostname for the redirected URL exposing requests users to session fixation attacks and potentially cookie stealing (CVE-2015-2296).

Solution

Update the affected python-requests and / or python3-requests packages.

See Also

http://advisories.mageia.org/MGASA-2014-0409.html

http://advisories.mageia.org/MGASA-2015-0120.html

Plugin Details

Severity: Medium

ID: 82386

File Name: mandriva_MDVSA-2015-133.nasl

Version: 1.3

Type: local

Published: 2015/03/30

Updated: 2019/08/02

Dependencies: 12634

Risk Information

Risk Factor: Medium

VPR Score: 4.7

CVSS v2.0

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:python-requests, p-cpe:/a:mandriva:linux:python3-requests, cpe:/o:mandriva:business_server:2

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 2015/03/29

Reference Information

CVE: CVE-2014-1829, CVE-2014-1830, CVE-2015-2296

MDVSA: 2015:133