Executive Summary

Summary
Title urllib3 vulnerabilities
Informations
Name USN-3990-1 First vendor Publication 2019-05-21
Vendor Ubuntu Last vendor Modification 2019-05-21
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04 - Ubuntu 18.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in urllib3.

Software Description: - python-urllib3: HTTP library with thread-safe connection pooling for Python

Details:

It was discovered that urllib3 incorrectly removed Authorization HTTP headers when handled cross-origin redirects. This could result in credentials being sent to unintended hosts. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-20060)

It was discovered that urllib3 incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. (CVE-2019-11236)

It was discovered that urllib3 incorrectly handled situations where a desired set of CA certificates were specified. This could result in certificates being accepted by the default CA certificates contrary to expectations. This issue only affected Ubuntu 18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-11324)

Update instructions:

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04:
python-urllib3 1.24.1-1ubuntu0.1
python3-urllib3 1.24.1-1ubuntu0.1

Ubuntu 18.10:
python-urllib3 1.22-1ubuntu0.18.10.1
python3-urllib3 1.22-1ubuntu0.18.10.1

Ubuntu 18.04 LTS:
python-urllib3 1.22-1ubuntu0.18.04.1
python3-urllib3 1.22-1ubuntu0.18.04.1

Ubuntu 16.04 LTS:
python-urllib3 1.13.1-2ubuntu0.16.04.3
python3-urllib3 1.13.1-2ubuntu0.16.04.3

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3990-1
CVE-2018-20060, CVE-2019-11236, CVE-2019-11324

Package Information:
https://launchpad.net/ubuntu/+source/python-urllib3/1.24.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/python-urllib3/1.22-1ubuntu0.18.10.1
https://launchpad.net/ubuntu/+source/python-urllib3/1.22-1ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/python-urllib3/1.13.1-2ubuntu0.16.04.3

Original Source

Url : http://www.ubuntu.com/usn/USN-3990-1

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-295 Certificate Issues
50 % CWE-93 Failure to Sanitize CRLF Sequences ('CRLF Injection')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3
Os 4
Os 3

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2019-07-30 12:14:11
  • Multiple Updates
2019-05-21 17:18:47
  • First insertion