|
|
Subscribe / Log in / New account

Debian alert DLA-2954-1 (python-treq)

From:  Chris Lamb <lamby@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2954-1] python-treq security update
Date:  Fri, 18 Mar 2022 06:46:27 -0400
Message-ID:  <164760034185.695155.1110900786804304308@copycat>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2954-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb March 18, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-treq Version : 15.1.0-1+deb9u1 CVE ID : CVE-2022-23607 Debian Bug : #1005041 It was discovered that there was an information disclosure issue in python-treq, a high-level library/API for making HTTP requests using the Twisted network programming library. HTTP cookies were not bound to a single domain and were instead sent to every domain. For Debian 9 "Stretch", this problem has been fixed in version 15.1.0-1+deb9u1. We recommend that you upgrade your python-treq packages. For the detailed security status of python-treq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-treq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmI0YtIACgkQHpU+J9Qx HljrrRAAs4oTsXufgSjgnR/Py/nsKBKQM5WLY00EqPWgi7B4RXyDVnSpk3jkG0Ty OWvHH2gp3zvK6TmTfBuGhrgOhoiqEmjQAmiP3Nf+90xUY9nIL3V2X7/zenf8Pp3s IuRH+A59vMOVGNantsrs1oHs7lXO7jEjM+f52G2Wi7V04ZKIh0aQNkbdRAyHGaVw 1AzpYGHOS1QSNz7jsWjColmSkNkE0W0RG/dwvaCsCjWva/4pT4gvgcuLox3oCdEp ARegun3BXGmmux5IoK78Hg22gzcUTY8ckg7pSYNDQkXEbOIWttxuB3A2bkXXr2x5 SeI6ThRFfFWeDcmJnY2K1SwW0MRJ0uUfXEj+WmCf9pTyFC8dfJmMFbEcXlwNtimp wP43UMVqVwsrL9VYAjh16kDMCRj7Pq40/l0osWYfm/OdZnn5h6Nf4HxW2WKwZfAS vG4tlIlrjRh8LINu/Fd/XRCWmRe9AfUDHfgQe+iS7vG/nJ8lYMwojlXzOmyYOvPh H9rxaKXpWmsoB9CzYIRgrEcBdpkzBHtM6D9fhpREgl05zI+eJlfbifuvfzEztHVi 1JkjageF3LsIkoV4uc2EWFtaYGsf3F8ceBnmgAg75Fl+Z402J/PglPnsMUuTcWRx HIaLTUIKZVIh088J/sVHb9FFvki7com6UMbJ6WIVSL8JRVTfmb4= =3qWQ -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds