[ubuntu/noble-security] python-pip 24.0+dfsg-1ubuntu1.3 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Tue Sep 23 12:08:57 UTC 2025
python-pip (24.0+dfsg-1ubuntu1.3) noble-security; urgency=medium
* SECURITY UPDATE: http body leakage via http redirect
- debian/patches/CVE-2023-45803.patch: removes the body from the
http request when it is redirected to a different origin and the
http verb is changed to GET.
- CVE-2023-45803
* SECURITY UPDATE: resource exhaustion
- debian/patches/CVE-2024-3651.patch: checks input before processing
- CVE-2024-3651
* SECURITY UPDATE: Information Leak
- debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
lookup instead of netloc
- CVE-2024-47081
Date: 2025-09-22 20:15:13.652713+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/python-pip/24.0+dfsg-1ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list