Your message dated Mon, 18 Aug 2025 14:43:39 +0100
with message-id <[email protected]>
and subject line Re: Bug#1107368: requests: CVE-2024-47081
has caused the Debian Bug report #1107368,
regarding requests: CVE-2024-47081
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1107368: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107368
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: requests
Version: 2.32.3+dfsg-5
Severity: important
Tags: security upstream
Forwarded: https://github.com/psf/requests/pull/6965
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for requests.

CVE-2024-47081[0].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-47081
    https://www.cve.org/CVERecord?id=CVE-2024-47081
[1] https://github.com/psf/requests/pull/6965
[2] 
https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: requests
Source-Version: 2.32.4+dfsg-1

On Fri, Jun 06, 2025 at 02:38:36PM +0200, Salvatore Bonaccorso wrote:
The following vulnerability was published for requests.

CVE-2024-47081[0].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-47081
   https://www.cve.org/CVERecord?id=CVE-2024-47081
[1] https://github.com/psf/requests/pull/6965
[2] 
https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef

requests (2.32.4+dfsg-1) unstable; urgency=medium

  * Team upload.
  * New upstream release.
    - CVE-2024-47081: Fixed an issue where a maliciously crafted URL and
      trusted environment will retrieve credentials for the wrong
      hostname/machine from a netrc file (closes: #1107368).
  * Avoid harmless "date: invalid date '@'" error in autopkgtest.

 -- Colin Watson <[email protected]>  Mon, 18 Aug 2025 11:18:19 +0100

(I didn't notice the CVE when preparing this update for other reasons; I retroactively added it to the changelog.)

--
Colin Watson (he/him)                              [[email protected]]

--- End Message ---

Reply via email to