[ubuntu/noble-security] python-pip 24.0+dfsg-1ubuntu1.3 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Tue Sep 23 12:08:57 UTC 2025


python-pip (24.0+dfsg-1ubuntu1.3) noble-security; urgency=medium

  * SECURITY UPDATE: http body leakage via http redirect
    - debian/patches/CVE-2023-45803.patch: removes the body from the
      http request when it is redirected to a different origin and the
      http verb is changed to GET.
    - CVE-2023-45803
  * SECURITY UPDATE: resource exhaustion
    - debian/patches/CVE-2024-3651.patch: checks input before processing
    - CVE-2024-3651
  * SECURITY UPDATE: Information Leak
    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
      lookup instead of netloc
    - CVE-2024-47081

Date: 2025-09-22 20:15:13.652713+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/python-pip/24.0+dfsg-1ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list