[ubuntu-cloud-archive/cloud-tools-proposed] requests (Accepted)

Scott Moser smoser at ubuntu.com
Fri Feb 6 16:08:28 UTC 2015


 requests (2.2.1-1ubuntu0.1~ctools0) precise; urgency=medium
 .
   * New update for the Ubuntu Cloud Archive.
 .
 requests (2.2.1-1ubuntu0.1) trusty-security; urgency=medium
 .
   * SECURITY UPDATE: Authorization header disclosure on redirect
     - debian/patches/CVE-2014-1829.patch: if redirected, strip
       authentication header in requests/sessions.py, add
       should_bypass_proxies() to requests/utils.py.
     - CVE-2014-1829
   * SECURITY UPDATE: Proxy-Authorization header disclosure on redirect
     - debian/patches/CVE-2014-1830.patch: also strip proxy headers in
       requests/sessions.py, added test to test_requests.py.
     - CVE-2014-1830
 .
 requests (2.2.1-1) unstable; urgency=medium
 .
   * New upstream release
   * debian/control
     - Bumped Standards-Version to 3.9.5 (no changes needed)
   * debian/copyright
     - Updated copyright years
   * debian/patches/02_use-system-chardet-and-urllib3.patches
     - Refreshed

Date: Fri, 06 Feb 2015 07:25:01 -0500
Changed-By: Scott Moser <smoser at ubuntu.com>
Signed-By: Scott Moser <smoser at ubuntu.com> 
Published-By: Scott Moser <smoser at ubuntu.com>


More information about the Cloud-tools-changes mailing list