oss-sec mailing list archives

Re: CVE request: Python HTTP header injection in urrlib2/urllib/httplib/http.client


From: Cedric Buissart <cbuissar () redhat com>
Date: Wed, 15 Jun 2016 10:42:48 +0200

Hi Tim,

On Tue, Jun 14, 2016 at 11:16 PM, Tim <tim-security () sentinelchicken org>
wrote:


In the mean time, do you happen to have specific information on which
versions of the 2.x and 3.x upstream branches were affected/fixed?


Reproducible on all python versions I tested : 2.4, 2.6, 2.7, 3.4 and 3.5

Fixed branches :
3.4 / 3.5 : revision 94952 : https://hg.python.org/cpython/rev/bf3e1c9b80e9
2.7 : revision 94951 : https://hg.python.org/cpython/rev/1c45047c5102

Regards,

-- 
Cedric Buissart,
Product Security

Purkynova 99
Brno 612 45

Current thread: