Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 668716 (CVE-2018-18074) - <dev-python/requests-2.21.0-r1: Infoleak through crafted HTTP headers (CVE-2018-18074)
Summary: <dev-python/requests-2.21.0-r1: Infoleak through crafted HTTP headers (CVE-20...
Status: RESOLVED FIXED
Alias: CVE-2018-18074
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://github.com/requests/requests/...
Whiteboard: B3 [noglsa cve]
Keywords:
: 669942 (view as bug list)
Depends on:
Blocks:
 
Reported: 2018-10-15 13:14 UTC by Vlad K.
Modified: 2019-03-10 23:15 UTC (History)
6 users (show)

See Also:
Package list:
dev-python/requests-2.21.0-r1
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Vlad K. 2018-10-15 13:14:25 UTC
"The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network." (Source: NVD)

* Upstream issue:
  https://github.com/requests/requests/issues/4716

* Patch:
  https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff


--

Gentoo Security Scout
Vladimir Krstulja
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2018-10-31 05:31:01 UTC
*** Bug 669942 has been marked as a duplicate of this bug. ***
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2018-10-31 05:33:01 UTC
https://github.com/requests/requests/blob/v2.20.0/HISTORY.md
Comment 3 Mart Raudsepp gentoo-dev 2019-02-11 18:30:15 UTC
ping python@..
Comment 4 Virgil Dupras (RETIRED) gentoo-dev 2019-02-11 19:28:42 UTC
The updated ebuild has been in the tree for a while now. Arches, please stabilize. Thanks!
Comment 5 Mart Raudsepp gentoo-dev 2019-02-12 14:56:57 UTC
arm64 stable
Comment 6 Rolf Eike Beer archtester 2019-02-12 21:18:51 UTC
sparc done
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2019-02-12 21:25:32 UTC
ppc64 stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2019-02-12 21:28:33 UTC
ppc stable
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2019-02-12 21:32:34 UTC
ia64 stable
Comment 10 Sergei Trofimovich (RETIRED) gentoo-dev 2019-02-12 21:33:28 UTC
hppa stable
Comment 11 Markus Meier gentoo-dev 2019-02-13 19:09:33 UTC
arm stable
Comment 12 Thomas Deutschmann (RETIRED) gentoo-dev 2019-02-15 15:49:42 UTC
x86 stable
Comment 13 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-02-15 18:06:47 UTC
amd64 stable
Comment 14 Matt Turner gentoo-dev 2019-03-02 20:46:32 UTC
alpha stable
Comment 15 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-03-03 06:27:00 UTC
sh stable
Comment 16 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-03-03 06:27:20 UTC
s390 stable
Comment 17 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-03-03 06:27:43 UTC
m68k stable
Comment 18 Aaron Bauman (RETIRED) gentoo-dev 2019-03-10 04:22:15 UTC
@maintainer, please drop vulnerable.
Comment 19 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2019-03-10 07:10:25 UTC
At a first glance, stable version of app-emulation/docker-compose is in the way.  Filed [1] to look for more.

[1]:https://github.com/gentoo/gentoo/pull/11325
Comment 20 Larry the Git Cow gentoo-dev 2019-03-10 08:33:53 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=aa525ecc052be76963def5685c8b9079024a3973

commit aa525ecc052be76963def5685c8b9079024a3973
Author:     Mikle Kolyada <zlogene@gentoo.org>
AuthorDate: 2019-03-10 08:33:34 +0000
Commit:     Mikle Kolyada <zlogene@gentoo.org>
CommitDate: 2019-03-10 08:33:34 +0000

    dev-python/requests: Security cleanup
    
    Closes: https://bugs.gentoo.org/668716
    Signed-off-by: Mikle Kolyada <zlogene@gentoo.org>
    Package-Manager: Portage-2.3.51, Repoman-2.3.11

 dev-python/requests/Manifest                  |  1 -
 dev-python/requests/requests-2.18.4-r1.ebuild | 52 ---------------------------
 2 files changed, 53 deletions(-)