Oval Definition:oval:org.opensuse.security:def:60984
Revision Date:2020-12-01Version:1
Title:Security update for python3-requests (Moderate)
Description:
This update for python3-requests provides the following fix:

python-requests was updated to 2.20.1.

Update to version 2.20.1:

* Fixed bug with unintended Authorization header stripping for
redirects using default ports (http/80, https/443).

Update to version 2.20.0:

* Bugfixes

+ Content-Type header parsing is now case-insensitive
(e.g. charset=utf8 v Charset=utf8).
+ Fixed exception leak where certain redirect urls would raise
uncaught urllib3 exceptions.
+ Requests removes Authorization header from requests redirected
from https to http on the same hostname. (CVE-2018-18074)
+ should_bypass_proxies now handles URIs without hostnames
(e.g. files).

Update to version 2.19.1:

* Fixed issue where status_codes.py’s init function failed trying
to append to a __doc__ value of None.

Update to version 2.19.0:

* Improvements

+ Warn about possible slowdown with cryptography version < 1.3.4
+ Check host in proxy URL, before forwarding request to adapter.
+ Maintain fragments properly across redirects. (RFC7231 7.1.2)
+ Removed use of cgi module to expedite library load time.
+ Added support for SHA-256 and SHA-512 digest auth algorithms.
+ Minor performance improvement to Request.content.

* Bugfixes

+ Parsing empty Link headers with parse_header_links() no longer
return one bogus entry.
+ Fixed issue where loading the default certificate bundle from
a zip archive would raise an IOError.
+ Fixed issue with unexpected ImportError on windows system
which do not support winreg module.
+ DNS resolution in proxy bypass no longer includes the username
and password in the request. This also fixes the issue of DNS
queries failing on macOS.
+ Properly normalize adapter prefixes for url comparison.
+ Passing None as a file pointer to the files param no longer
raises an exception.
+ Calling copy on a RequestsCookieJar will now preserve the
cookie policy correctly.

Update to version 2.18.4:

* Improvements

+ Error messages for invalid headers now include the header name
for easier debugging

Update to version 2.18.3:

* Improvements
+ Running $ python -m requests.help now includes the installed
version of idna.
* Bugfixes
+ Fixed issue where Requests would raise ConnectionError instead
of SSLError when encountering SSL problems when using urllib3
v1.22.

- Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https
connections will fail.
Family:unixClass:patch
Status:Reference(s):1027024
1027025
1027026
1040311
1040312
1040313
1048289
1048544
1049877
1050577
1050578
1050579
1050581
1054413
1055960
1073879
1077080
1082692
1085449
1093311
1111622
1111789
1120114
1120115
1120116
1120117
1120118
1120119
1120120
1120121
1120122
1122668
1123022
1124799
1124800
1124802
1124803
1124805
1124806
1124824
1124825
1124826
1124827
1125099
1129180
1130116
1131863
1132728
1132729
1132732
1132734
1134156
1134718
1140359
1146882
1146884
1154609
1160467
1160468
1167068
1170558
1171363
1174922
1174923
1176410
1177143
1178593
682920
761500
922448
929736
935252
945455
947357
961596
967128
CVE-2015-2296
CVE-2017-11624
CVE-2017-11625
CVE-2017-11626
CVE-2017-11627
CVE-2017-12595
CVE-2017-17997
CVE-2017-18926
CVE-2017-2862
CVE-2017-2870
CVE-2017-6312
CVE-2017-6313
CVE-2017-6314
CVE-2017-9208
CVE-2017-9209
CVE-2017-9210
CVE-2018-1417
CVE-2018-15126
CVE-2018-15127
CVE-2018-18074
CVE-2018-20019
CVE-2018-20020
CVE-2018-20021
CVE-2018-20022
CVE-2018-20023
CVE-2018-20024
CVE-2018-2783
CVE-2018-2790
CVE-2018-2794
CVE-2018-2795
CVE-2018-2796
CVE-2018-2797
CVE-2018-2798
CVE-2018-2799
CVE-2018-2800
CVE-2018-2814
CVE-2018-6307
CVE-2018-7320
CVE-2018-7321
CVE-2018-7322
CVE-2018-7323
CVE-2018-7324
CVE-2018-7325
CVE-2018-7326
CVE-2018-7327
CVE-2018-7328
CVE-2018-7329
CVE-2018-7330
CVE-2018-7331
CVE-2018-7332
CVE-2018-7333
CVE-2018-7334
CVE-2018-7335
CVE-2018-7336
CVE-2018-7337
CVE-2018-7417
CVE-2018-7418
CVE-2018-7419
CVE-2018-7420
CVE-2018-7421
CVE-2019-10245
CVE-2019-12973
CVE-2019-14811
CVE-2019-14812
CVE-2019-14813
CVE-2019-14817
CVE-2019-14896
CVE-2019-14897
CVE-2019-18197
CVE-2019-2602
CVE-2019-2684
CVE-2019-2697
CVE-2019-2698
CVE-2019-3814
CVE-2019-3835
CVE-2019-3839
CVE-2019-7524
CVE-2019-7572
CVE-2019-7573
CVE-2019-7574
CVE-2019-7575
CVE-2019-7576
CVE-2019-7577
CVE-2019-7578
CVE-2019-7635
CVE-2019-7636
CVE-2019-7637
CVE-2019-7638
CVE-2020-12108
CVE-2020-12137
CVE-2020-12673
CVE-2020-12674
CVE-2020-25219
CVE-2020-26154
SUSE-SU-2017:2381-1
SUSE-SU-2018:0811-1
SUSE-SU-2018:1764-1
SUSE-SU-2018:3066-1
SUSE-SU-2019:2478-1
SUSE-SU-2020:0920-2
SUSE-SU-2020:1301-1
SUSE-SU-2020:1792-1
SUSE-SU-2020:2274-1
SUSE-SU-2020:2900-1
SUSE-SU-2020:3351-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • fuse-overlayfs-0.4.1-lp151.2 is installed
  • OR fuse3-3.6.1-lp151.2 is installed
  • OR fuse3-devel-3.6.1-lp151.2 is installed
  • OR fuse3-doc-3.6.1-lp151.2 is installed
  • OR libcontainers-common-20190401-lp151.2.3 is installed
  • OR libfuse3-3-3.6.1-lp151.2 is installed
  • OR podman-1.4.4-lp151.3.3 is installed
  • OR podman-cni-config-1.4.4-lp151.3.3 is installed
  • OR slirp4netns-0.3.0-lp151.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • LibVNCServer-0.9.10-lp152.9.8 is installed
  • OR LibVNCServer-devel-0.9.10-lp152.9.8 is installed
  • OR libvncclient0-0.9.10-lp152.9.8 is installed
  • OR libvncserver0-0.9.10-lp152.9.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • gdk-pixbuf-2.34.0-19.5 is installed
  • OR gdk-pixbuf-lang-2.34.0-19.5 is installed
  • OR gdk-pixbuf-query-loaders-2.34.0-19.5 is installed
  • OR gdk-pixbuf-query-loaders-32bit-2.34.0-19.5 is installed
  • OR libgdk_pixbuf-2_0-0-2.34.0-19.5 is installed
  • OR libgdk_pixbuf-2_0-0-32bit-2.34.0-19.5 is installed
  • OR typelib-1_0-GdkPixbuf-2_0-2.34.0-19.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • ghostscript-9.27-23.28 is installed
  • OR ghostscript-x11-9.27-23.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_176-94_88-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_24-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND mailman-2.1.17-3.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.45-38.37 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.45-38.37 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.45-38.37 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.45-38.37 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • colord-gtk-lang-0.1.26-6 is installed
  • OR libcolord-gtk1-0.1.26-6 is installed
  • OR libcolord2-1.3.3-12 is installed
  • OR libcolord2-32bit-1.3.3-12 is installed
  • OR libcolorhug2-1.3.3-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • xen-4.11.4_06-2.33 is installed
  • OR xen-doc-html-4.11.4_06-2.33 is installed
  • OR xen-libs-4.11.4_06-2.33 is installed
  • OR xen-libs-32bit-4.11.4_06-2.33 is installed
  • OR xen-tools-4.11.4_06-2.33 is installed
  • OR xen-tools-domU-4.11.4_06-2.33 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.28.4-2.59 is installed
  • OR libwebkit2gtk-4_0-37-2.28.4-2.59 is installed
  • OR libwebkit2gtk3-lang-2.28.4-2.59 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.28.4-2.59 is installed
  • OR typelib-1_0-WebKit2-4_0-2.28.4-2.59 is installed
  • OR typelib-1_0-WebKit2WebExtension-4_0-2.28.4-2.59 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.28.4-2.59 is installed
  • OR webkit2gtk3-2.28.4-2.59 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-ipaddress-1.0.22-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • python-certifi-2018.4.16-3.6 is installed
  • OR python-chardet-3.0.4-5.6 is installed
  • OR python-urllib3-1.22-3.20 is installed
  • OR python3-certifi-2018.4.16-3.6 is installed
  • OR python3-chardet-3.0.4-5.6 is installed
  • OR python3-requests-2.20.1-5 is installed
  • OR python3-urllib3-1.22-3.20 is installed
  • BACK