LWN.net Logo

python-httplib2: information disclosure

Package(s):python-httplib2 CVE #(s):
Created:February 27, 2012 Updated:February 29, 2012
Description: From the Ubuntu advisory:

The httplib2 Python library earlier than version 0.7.0 did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information in applications that used the httplib2 library.

Alerts:
Ubuntu USN-1375-1 2012-02-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds