Oval Definition:oval:org.opensuse.security:def:63968
Revision Date:2020-12-01Version:1
Title:Security update for python3-requests (Moderate)
Description:
This update for python3-requests provides the following fix:

python-requests was updated to 2.20.1.

Update to version 2.20.1:

* Fixed bug with unintended Authorization header stripping for
redirects using default ports (http/80, https/443).

Update to version 2.20.0:

* Bugfixes

+ Content-Type header parsing is now case-insensitive
(e.g. charset=utf8 v Charset=utf8).
+ Fixed exception leak where certain redirect urls would raise
uncaught urllib3 exceptions.
+ Requests removes Authorization header from requests redirected
from https to http on the same hostname. (CVE-2018-18074)
+ should_bypass_proxies now handles URIs without hostnames
(e.g. files).

Update to version 2.19.1:

* Fixed issue where status_codes.py’s init function failed trying
to append to a __doc__ value of None.

Update to version 2.19.0:

* Improvements

+ Warn about possible slowdown with cryptography version < 1.3.4
+ Check host in proxy URL, before forwarding request to adapter.
+ Maintain fragments properly across redirects. (RFC7231 7.1.2)
+ Removed use of cgi module to expedite library load time.
+ Added support for SHA-256 and SHA-512 digest auth algorithms.
+ Minor performance improvement to Request.content.

* Bugfixes

+ Parsing empty Link headers with parse_header_links() no longer
return one bogus entry.
+ Fixed issue where loading the default certificate bundle from
a zip archive would raise an IOError.
+ Fixed issue with unexpected ImportError on windows system
which do not support winreg module.
+ DNS resolution in proxy bypass no longer includes the username
and password in the request. This also fixes the issue of DNS
queries failing on macOS.
+ Properly normalize adapter prefixes for url comparison.
+ Passing None as a file pointer to the files param no longer
raises an exception.
+ Calling copy on a RequestsCookieJar will now preserve the
cookie policy correctly.

Update to version 2.18.4:

* Improvements

+ Error messages for invalid headers now include the header name
for easier debugging

Update to version 2.18.3:

* Improvements
+ Running $ python -m requests.help now includes the installed
version of idna.
* Bugfixes
+ Fixed issue where Requests would raise ConnectionError instead
of SSLError when encountering SSL problems when using urllib3
v1.22.

- Add ca-certificates (and ca-certificates-mozilla) to dependencies, otherwise https
connections will fail.
Family:unixClass:patch
Status:Reference(s):1051510
1052478
1052484
1054413
1065729
1071995
1073879
1079603
1085030
1091109
1104967
1105084
1111622
1114279
1122668
1144333
1146569
1146571
1146572
1146702
1148868
1150660
1152107
1152472
1152624
1158983
1159058
1160968
1161016
1162002
1162063
1162972
1166751
1168081
1169194
1169514
1169795
1170011
1170592
1170618
1171124
1171424
1171558
1171673
1171732
1171761
1171868
1171904
1172257
1172344
1172458
1172484
1172515
1172759
1172775
1172781
1172782
1172783
1172999
1173265
1173280
1173428
1173462
1173514
1173567
1173573
1174115
1174462
1174543
1176315
1177351
1177352
761500
922448
929736
935252
945455
947357
961596
967128
CVE-2015-2296
CVE-2017-12481
CVE-2017-12482
CVE-2017-2807
CVE-2017-2808
CVE-2018-18074
CVE-2018-6942
CVE-2019-15142
CVE-2019-15143
CVE-2019-15144
CVE-2019-15145
CVE-2019-16746
CVE-2019-20810
CVE-2019-20908
CVE-2019-4732
CVE-2020-0305
CVE-2020-0556
CVE-2020-10766
CVE-2020-10767
CVE-2020-10768
CVE-2020-10769
CVE-2020-10773
CVE-2020-12771
CVE-2020-12888
CVE-2020-13974
CVE-2020-14416
CVE-2020-15393
CVE-2020-15780
CVE-2020-17507
CVE-2020-2583
CVE-2020-2593
CVE-2020-2604
CVE-2020-2659
CVE-2020-6510
CVE-2020-6511
CVE-2020-6512
CVE-2020-6513
CVE-2020-6514
CVE-2020-6515
CVE-2020-6516
CVE-2020-6517
CVE-2020-6518
CVE-2020-6519
CVE-2020-6520
CVE-2020-6521
CVE-2020-6522
CVE-2020-6523
CVE-2020-6524
CVE-2020-6525
CVE-2020-6526
CVE-2020-6527
CVE-2020-6528
CVE-2020-6529
CVE-2020-6530
CVE-2020-6531
CVE-2020-6533
CVE-2020-6534
CVE-2020-6535
CVE-2020-6536
CVE-2020-7069
CVE-2020-7070
openSUSE-SU-2019:1779-1
openSUSE-SU-2019:2219-1
openSUSE-SU-2020:0704-1
openSUSE-SU-2020:1148-1
openSUSE-SU-2020:1703-1
SUSE-SU-2020:0528-1
SUSE-SU-2020:1792-1
SUSE-SU-2020:2751-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.1 NonFree
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND ledger-3.1.3-lp151.3.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 NonFree is installed
  • AND opera-70.0.3728.71-lp151.2.24 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • apache2-mod_php7-7.4.6-lp152.2.9 is installed
  • OR php7-7.4.6-lp152.2.9 is installed
  • OR php7-bcmath-7.4.6-lp152.2.9 is installed
  • OR php7-bz2-7.4.6-lp152.2.9 is installed
  • OR php7-calendar-7.4.6-lp152.2.9 is installed
  • OR php7-ctype-7.4.6-lp152.2.9 is installed
  • OR php7-curl-7.4.6-lp152.2.9 is installed
  • OR php7-dba-7.4.6-lp152.2.9 is installed
  • OR php7-devel-7.4.6-lp152.2.9 is installed
  • OR php7-dom-7.4.6-lp152.2.9 is installed
  • OR php7-embed-7.4.6-lp152.2.9 is installed
  • OR php7-enchant-7.4.6-lp152.2.9 is installed
  • OR php7-exif-7.4.6-lp152.2.9 is installed
  • OR php7-fastcgi-7.4.6-lp152.2.9 is installed
  • OR php7-fileinfo-7.4.6-lp152.2.9 is installed
  • OR php7-firebird-7.4.6-lp152.2.9 is installed
  • OR php7-fpm-7.4.6-lp152.2.9 is installed
  • OR php7-ftp-7.4.6-lp152.2.9 is installed
  • OR php7-gd-7.4.6-lp152.2.9 is installed
  • OR php7-gettext-7.4.6-lp152.2.9 is installed
  • OR php7-gmp-7.4.6-lp152.2.9 is installed
  • OR php7-iconv-7.4.6-lp152.2.9 is installed
  • OR php7-intl-7.4.6-lp152.2.9 is installed
  • OR php7-json-7.4.6-lp152.2.9 is installed
  • OR php7-ldap-7.4.6-lp152.2.9 is installed
  • OR php7-mbstring-7.4.6-lp152.2.9 is installed
  • OR php7-mysql-7.4.6-lp152.2.9 is installed
  • OR php7-odbc-7.4.6-lp152.2.9 is installed
  • OR php7-opcache-7.4.6-lp152.2.9 is installed
  • OR php7-openssl-7.4.6-lp152.2.9 is installed
  • OR php7-pcntl-7.4.6-lp152.2.9 is installed
  • OR php7-pdo-7.4.6-lp152.2.9 is installed
  • OR php7-pgsql-7.4.6-lp152.2.9 is installed
  • OR php7-phar-7.4.6-lp152.2.9 is installed
  • OR php7-posix-7.4.6-lp152.2.9 is installed
  • OR php7-readline-7.4.6-lp152.2.9 is installed
  • OR php7-shmop-7.4.6-lp152.2.9 is installed
  • OR php7-snmp-7.4.6-lp152.2.9 is installed
  • OR php7-soap-7.4.6-lp152.2.9 is installed
  • OR php7-sockets-7.4.6-lp152.2.9 is installed
  • OR php7-sodium-7.4.6-lp152.2.9 is installed
  • OR php7-sqlite-7.4.6-lp152.2.9 is installed
  • OR php7-sysvmsg-7.4.6-lp152.2.9 is installed
  • OR php7-sysvsem-7.4.6-lp152.2.9 is installed
  • OR php7-sysvshm-7.4.6-lp152.2.9 is installed
  • OR php7-test-7.4.6-lp152.2.9 is installed
  • OR php7-tidy-7.4.6-lp152.2.9 is installed
  • OR php7-tokenizer-7.4.6-lp152.2.9 is installed
  • OR php7-xmlreader-7.4.6-lp152.2.9 is installed
  • OR php7-xmlrpc-7.4.6-lp152.2.9 is installed
  • OR php7-xmlwriter-7.4.6-lp152.2.9 is installed
  • OR php7-xsl-7.4.6-lp152.2.9 is installed
  • OR php7-zip-7.4.6-lp152.2.9 is installed
  • OR php7-zlib-7.4.6-lp152.2.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • python-certifi-2018.4.16-3.6 is installed
  • OR python-chardet-3.0.4-5.6 is installed
  • OR python-urllib3-1.22-3.20 is installed
  • OR python3-certifi-2018.4.16-3.6 is installed
  • OR python3-chardet-3.0.4-5.6 is installed
  • OR python3-requests-2.20.1-5 is installed
  • OR python3-urllib3-1.22-3.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • kernel-default-4.12.14-95.57 is installed
  • OR kernel-default-base-4.12.14-95.57 is installed
  • OR kernel-default-devel-4.12.14-95.57 is installed
  • OR kernel-devel-4.12.14-95.57 is installed
  • OR kernel-macros-4.12.14-95.57 is installed
  • OR kernel-source-4.12.14-95.57 is installed
  • OR kernel-syms-4.12.14-95.57 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • libQt5Concurrent5-5.6.2-6.25 is installed
  • OR libQt5Core5-5.6.2-6.25 is installed
  • OR libQt5DBus5-5.6.2-6.25 is installed
  • OR libQt5Gui5-5.6.2-6.25 is installed
  • OR libQt5Network5-5.6.2-6.25 is installed
  • OR libQt5OpenGL5-5.6.2-6.25 is installed
  • OR libQt5PrintSupport5-5.6.2-6.25 is installed
  • OR libQt5Sql5-5.6.2-6.25 is installed
  • OR libQt5Sql5-mysql-5.6.2-6.25 is installed
  • OR libQt5Sql5-postgresql-5.6.2-6.25 is installed
  • OR libQt5Sql5-sqlite-5.6.2-6.25 is installed
  • OR libQt5Sql5-unixODBC-5.6.2-6.25 is installed
  • OR libQt5Test5-5.6.2-6.25 is installed
  • OR libQt5Widgets5-5.6.2-6.25 is installed
  • OR libQt5Xml5-5.6.2-6.25 is installed
  • OR libqt5-qtbase-5.6.2-6.25 is installed
  • BACK