Source: python-httplib2
Version: 0.18.1-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for python-httplib2.

CVE-2021-21240[0]:
| httplib2 is a comprehensive HTTP client library for Python. In
| httplib2 before version 0.19.0, a malicious server which responds with
| long series of "\xa0" characters in the "www-authenticate" header may
| cause Denial of Service (CPU burn while parsing header) of the
| httplib2 client accessing said server. This is fixed in version 0.19.0
| which contains a new implementation of auth headers parsing using the
| pyparsing library.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2021-21240
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21240
[1] https://github.com/httplib2/httplib2/security/advisories/GHSA-93xj-8mrv-444m

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to