Oval Definition:oval:org.opensuse.security:def:60718
Revision Date:2020-12-01Version:1
Title:Security update for python3-requests (Moderate)
Description:
This update for python3-requests provides the following fix:

python-requests was updated to 2.20.1.

Update to version 2.20.1:

* Fixed bug with unintended Authorization header stripping for
redirects using default ports (http/80, https/443).

Update to version 2.20.0:

* Bugfixes

+ Content-Type header parsing is now case-insensitive
(e.g. charset=utf8 v Charset=utf8).
+ Fixed exception leak where certain redirect urls would raise
uncaught urllib3 exceptions.
+ Requests removes Authorization header from requests redirected
from https to http on the same hostname. (CVE-2018-18074)
+ should_bypass_proxies now handles URIs without hostnames
(e.g. files).

Update to version 2.19.1:

* Fixed issue where status_codes.py’s init function failed trying
to append to a __doc__ value of None.

Update to version 2.19.0:

* Improvements

+ Warn about possible slowdown with cryptography version < 1.3.4
+ Check host in proxy URL, before forwarding request to adapter.
+ Maintain fragments properly across redirects. (RFC7231 7.1.2)
+ Removed use of cgi module to expedite library load time.
+ Added support for SHA-256 and SHA-512 digest auth algorithms.
+ Minor performance improvement to Request.content.

* Bugfixes

+ Parsing empty Link headers with parse_header_links() no longer
return one bogus entry.
+ Fixed issue where loading the default certificate bundle from
a zip archive would raise an IOError.
+ Fixed issue with unexpected ImportError on windows system
which do not support winreg module.
+ DNS resolution in proxy bypass no longer includes the username
and password in the request. This also fixes the issue of DNS
queries failing on macOS.
+ Properly normalize adapter prefixes for url comparison.
+ Passing None as a file pointer to the files param no longer
raises an exception.
+ Calling copy on a RequestsCookieJar will now preserve the
cookie policy correctly.

Update to version 2.18.4:

* Improvements

+ Error messages for invalid headers now include the header name
for easier debugging

Update to version 2.18.3:

* Improvements
+ Running $ python -m requests.help now includes the installed
version of idna.
* Bugfixes
+ Fixed issue where Requests would raise ConnectionError instead
of SSLError when encountering SSL problems when using urllib3
v1.22.

- Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https
connections will fail.
Family:unixClass:patch
Status:Reference(s):1008037
1008038
1010940
1019021
1023895
1027282
1027353
1038785
1041090
1042670
1046077
1052261
1054413
1056094
1056134
1059235
1073269
1073748
1073879
1074318
1078326
1078485
1080682
1081164
1081690
1081750
1084650
1086001
1087813
1090638
1097775
1102126
1102775
1103040
1104457
1109160
1109957
1110723
1111122
1111622
1112959
1117080
1118367
1118368
1118896
1120386
1122668
1123561
1126503
1133147
1137325
1137479
1137528
1141322
1142121
1142542
1144453
1145092
1145929
1149591
1149792
1153108
1153452
1153830
1154118
1154231
1154232
1154830
1154844
1155094
1155689
1156317
1156321
1156331
1157155
1157157
1157303
1157804
1157968
1157969
1158021
1158527
1158642
1158819
1159035
1159199
1159285
1159297
1159447
1159819
1159841
1159908
1159910
1159911
1159912
1160195
1161586
1161919
1162224
1162227
1162367
1162825
1162928
1162929
1162931
1163508
1163971
1164009
1164051
1164069
1164078
1164133
1164134
1164135
1164136
1164137
1164138
1164139
1164140
1164846
1165022
1165111
1165311
1165393
1165873
1165881
1165894
1165984
1165985
1166389
1167421
1167423
1167440
1167532
1167629
1168075
1168295
1168424
1168669
1168829
1168854
1169746
1170056
1170345
1170411
1170778
1170847
1170908
1171162
1171561
1171740
1171823
1171978
1172450
1173022
1173413
1173416
1173418
1174006
1174145
1174242
1174302
1174583
1174662
1175484
1175986
1175993
1177120
1177948
1178671
761500
922448
929736
935252
945401
945455
947357
961596
967128
980486
CVE-2015-2296
CVE-2016-8614
CVE-2016-8628
CVE-2016-8647
CVE-2016-9587
CVE-2017-12424
CVE-2017-17833
CVE-2017-17973
CVE-2017-18255
CVE-2017-7466
CVE-2017-7550
CVE-2017-9935
CVE-2018-10875
CVE-2018-11779
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-14680
CVE-2018-14681
CVE-2018-14682
CVE-2018-15378
CVE-2018-16837
CVE-2018-16859
CVE-2018-16876
CVE-2018-18065
CVE-2018-18074
CVE-2018-18623
CVE-2018-18624
CVE-2018-18625
CVE-2018-20856
CVE-2018-21008
CVE-2018-5741
CVE-2018-5784
CVE-2019-0202
CVE-2019-10156
CVE-2019-10206
CVE-2019-10208
CVE-2019-10217
CVE-2019-10220
CVE-2019-11091
CVE-2019-11745
CVE-2019-13272
CVE-2019-14615
CVE-2019-14846
CVE-2019-14856
CVE-2019-14858
CVE-2019-14864
CVE-2019-14896
CVE-2019-14897
CVE-2019-14904
CVE-2019-14905
CVE-2019-15239
CVE-2019-17006
CVE-2019-17006
CVE-2019-18348
CVE-2019-18675
CVE-2019-19066
CVE-2019-19319
CVE-2019-19447
CVE-2019-19767
CVE-2019-19768
CVE-2019-19844
CVE-2019-19965
CVE-2019-19966
CVE-2019-20054
CVE-2019-20096
CVE-2019-3701
CVE-2019-3828
CVE-2019-5108
CVE-2019-9455
CVE-2019-9458
CVE-2019-9674
CVE-2020-10177
CVE-2020-10378
CVE-2020-10684
CVE-2020-10685
CVE-2020-10690
CVE-2020-10691
CVE-2020-10720
CVE-2020-10729
CVE-2020-10744
CVE-2020-10942
CVE-2020-10994
CVE-2020-11110
CVE-2020-11494
CVE-2020-11608
CVE-2020-11609
CVE-2020-12321
CVE-2020-12399
CVE-2020-12402
CVE-2020-14330
CVE-2020-14332
CVE-2020-14365
CVE-2020-1733
CVE-2020-1734
CVE-2020-1735
CVE-2020-1736
CVE-2020-1737
CVE-2020-17376
CVE-2020-1738
CVE-2020-1739
CVE-2020-1740
CVE-2020-1746
CVE-2020-1753
CVE-2020-25032
CVE-2020-26137
CVE-2020-2732
CVE-2020-7471
CVE-2020-8492
CVE-2020-8616
CVE-2020-8617
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2020-8992
CVE-2020-9383
CVE-2020-9402
CVE-2020-9862
CVE-2020-9893
CVE-2020-9894
CVE-2020-9895
CVE-2020-9915
CVE-2020-9925
SUSE-SU-2017:2947-1
SUSE-SU-2018:1180-1
SUSE-SU-2019:2159-1
SUSE-SU-2020:0088-1
SUSE-SU-2020:1275-1
SUSE-SU-2020:1524-1
SUSE-SU-2020:1792-1
SUSE-SU-2020:1914-1
SUSE-SU-2020:2232-1
SUSE-SU-2020:3309-1
SUSE-SU-2020:3354-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libssh-0.7.5-lp150.5.3 is installed
  • OR libssh-devel-0.7.5-lp150.5.3 is installed
  • OR libssh-devel-doc-0.7.5-lp150.5.3 is installed
  • OR libssh4-0.7.5-lp150.5.3 is installed
  • OR libssh4-32bit-0.7.5-lp150.5.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • chromedriver-76.0.3809.87-lp151.2.15 is installed
  • OR chromium-76.0.3809.87-lp151.2.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND shadow-4.2.1-27.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • kernel-default-4.4.180-94.116 is installed
  • OR kernel-default-base-4.4.180-94.116 is installed
  • OR kernel-default-devel-4.4.180-94.116 is installed
  • OR kernel-devel-4.4.180-94.116 is installed
  • OR kernel-macros-4.4.180-94.116 is installed
  • OR kernel-source-4.4.180-94.116 is installed
  • OR kernel-syms-4.4.180-94.116 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libfreebl3-3.53.1-58.48 is installed
  • OR libfreebl3-32bit-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-3.53.1-58.48 is installed
  • OR libsoftokn3-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-32bit-3.53.1-58.48 is installed
  • OR mozilla-nspr-4.25-19.15 is installed
  • OR mozilla-nspr-32bit-4.25-19.15 is installed
  • OR mozilla-nspr-devel-4.25-19.15 is installed
  • OR mozilla-nss-3.53.1-58.48 is installed
  • OR mozilla-nss-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-devel-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-tools-3.53.1-58.48 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_176-94_88-default-6-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_24-6-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • openslp-2.0.0-18.17 is installed
  • OR openslp-32bit-2.0.0-18.17 is installed
  • OR openslp-server-2.0.0-18.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND clamav-0.100.2-33.18 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • xen-4.11.4_06-2.33 is installed
  • OR xen-doc-html-4.11.4_06-2.33 is installed
  • OR xen-libs-4.11.4_06-2.33 is installed
  • OR xen-libs-32bit-4.11.4_06-2.33 is installed
  • OR xen-tools-4.11.4_06-2.33 is installed
  • OR xen-tools-domU-4.11.4_06-2.33 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • python-certifi-2018.4.16-3.6 is installed
  • OR python-chardet-3.0.4-5.6 is installed
  • OR python-urllib3-1.22-3.20 is installed
  • OR python3-certifi-2018.4.16-3.6 is installed
  • OR python3-chardet-3.0.4-5.6 is installed
  • OR python3-requests-2.20.1-5 is installed
  • OR python3-urllib3-1.22-3.20 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • postgresql96-9.6.15-3.29 is installed
  • OR postgresql96-contrib-9.6.15-3.29 is installed
  • OR postgresql96-docs-9.6.15-3.29 is installed
  • OR postgresql96-libs-9.6.15-3.29 is installed
  • OR postgresql96-plperl-9.6.15-3.29 is installed
  • OR postgresql96-plpython-9.6.15-3.29 is installed
  • OR postgresql96-pltcl-9.6.15-3.29 is installed
  • OR postgresql96-server-9.6.15-3.29 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND python-Django1-1.11.20-3.6 is installed
  • BACK