Debian alert DLA-2954-1 (python-treq)
From: | Chris Lamb <lamby@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 2954-1] python-treq security update | |
Date: | Fri, 18 Mar 2022 06:46:27 -0400 | |
Message-ID: | <164760034185.695155.1110900786804304308@copycat> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2954-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb March 18, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-treq Version : 15.1.0-1+deb9u1 CVE ID : CVE-2022-23607 Debian Bug : #1005041 It was discovered that there was an information disclosure issue in python-treq, a high-level library/API for making HTTP requests using the Twisted network programming library. HTTP cookies were not bound to a single domain and were instead sent to every domain. For Debian 9 "Stretch", this problem has been fixed in version 15.1.0-1+deb9u1. We recommend that you upgrade your python-treq packages. For the detailed security status of python-treq please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-treq Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmI0YtIACgkQHpU+J9Qx HljrrRAAs4oTsXufgSjgnR/Py/nsKBKQM5WLY00EqPWgi7B4RXyDVnSpk3jkG0Ty OWvHH2gp3zvK6TmTfBuGhrgOhoiqEmjQAmiP3Nf+90xUY9nIL3V2X7/zenf8Pp3s IuRH+A59vMOVGNantsrs1oHs7lXO7jEjM+f52G2Wi7V04ZKIh0aQNkbdRAyHGaVw 1AzpYGHOS1QSNz7jsWjColmSkNkE0W0RG/dwvaCsCjWva/4pT4gvgcuLox3oCdEp ARegun3BXGmmux5IoK78Hg22gzcUTY8ckg7pSYNDQkXEbOIWttxuB3A2bkXXr2x5 SeI6ThRFfFWeDcmJnY2K1SwW0MRJ0uUfXEj+WmCf9pTyFC8dfJmMFbEcXlwNtimp wP43UMVqVwsrL9VYAjh16kDMCRj7Pq40/l0osWYfm/OdZnn5h6Nf4HxW2WKwZfAS vG4tlIlrjRh8LINu/Fd/XRCWmRe9AfUDHfgQe+iS7vG/nJ8lYMwojlXzOmyYOvPh H9rxaKXpWmsoB9CzYIRgrEcBdpkzBHtM6D9fhpREgl05zI+eJlfbifuvfzEztHVi 1JkjageF3LsIkoV4uc2EWFtaYGsf3F8ceBnmgAg75Fl+Z402J/PglPnsMUuTcWRx HIaLTUIKZVIh088J/sVHb9FFvki7com6UMbJ6WIVSL8JRVTfmb4= =3qWQ -----END PGP SIGNATURE-----