Vulnerability Bulletins

DSA-3146 requests - security update

   
Affected software Debian
 
Jakub Wilk discovered that in requests, an HTTP library for the Pythonlanguage, authentication information was improperly handled when aredirect occured. This would allow remote servers to obtain twodifferent types of sensitive information: proxy passwords from theProxy-Authorization header(CVE-2014-1830), or netrc passwords from the Authorization header(CVE-2014-1829).

More info:

https://www.debian.org/security/2015/dsa-3146