Boletines de Vulnerabilidades |
DSA-3146 requests - security update |
|
| Software afectado | Debian |
|
Jakub Wilk discovered that in requests, an HTTP library for the Pythonlanguage, authentication information was improperly handled when aredirect occured. This would allow remote servers to obtain twodifferent types of sensitive information: proxy passwords from theProxy-Authorization header(CVE-2014-1830), or netrc passwords from the Authorization header(CVE-2014-1829). More info: https://www.debian.org/security/2015/dsa-3146 |
|














