oss-sec mailing list archives
Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client
From: Cedric Buissart <cbuissar () redhat com>
Date: Wed, 15 Jun 2016 10:42:48 +0200
Hi Tim, On Tue, Jun 14, 2016 at 11:16 PM, Tim <tim-security () sentinelchicken org> wrote:
In the mean time, do you happen to have specific information on which versions of the 2.x and 3.x upstream branches were affected/fixed?
Reproducible on all python versions I tested : 2.4, 2.6, 2.7, 3.4 and 3.5 Fixed branches : 3.4 / 3.5 : revision 94952 : https://hg.python.org/cpython/rev/bf3e1c9b80e9 2.7 : revision 94951 : https://hg.python.org/cpython/rev/1c45047c5102 Regards, -- Cedric Buissart, Product Security Purkynova 99 Brno 612 45
Current thread:
- CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Cedric Buissart (Jun 14)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Tim (Jun 14)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Cedric Buissart (Jun 15)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Tim (Jun 15)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Cedric Buissart (Jun 17)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Marcus Meissner (Jun 23)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client cve-assign (Jun 23)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Cedric Buissart (Jun 15)
- Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client Tim (Jun 14)
