[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 2954-1] python-treq security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2954-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
March 18, 2022                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : python-treq
Version        : 15.1.0-1+deb9u1
CVE ID         : CVE-2022-23607
Debian Bug     : #1005041

It was discovered that there was an information disclosure issue in
python-treq, a high-level library/API for making HTTP requests using
the Twisted network programming library. HTTP cookies were not bound
to a single domain and were instead sent to every domain.

For Debian 9 "Stretch", this problem has been fixed in version
15.1.0-1+deb9u1.

We recommend that you upgrade your python-treq packages.

For the detailed security status of python-treq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-treq

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmI0YtIACgkQHpU+J9Qx
HljrrRAAs4oTsXufgSjgnR/Py/nsKBKQM5WLY00EqPWgi7B4RXyDVnSpk3jkG0Ty
OWvHH2gp3zvK6TmTfBuGhrgOhoiqEmjQAmiP3Nf+90xUY9nIL3V2X7/zenf8Pp3s
IuRH+A59vMOVGNantsrs1oHs7lXO7jEjM+f52G2Wi7V04ZKIh0aQNkbdRAyHGaVw
1AzpYGHOS1QSNz7jsWjColmSkNkE0W0RG/dwvaCsCjWva/4pT4gvgcuLox3oCdEp
ARegun3BXGmmux5IoK78Hg22gzcUTY8ckg7pSYNDQkXEbOIWttxuB3A2bkXXr2x5
SeI6ThRFfFWeDcmJnY2K1SwW0MRJ0uUfXEj+WmCf9pTyFC8dfJmMFbEcXlwNtimp
wP43UMVqVwsrL9VYAjh16kDMCRj7Pq40/l0osWYfm/OdZnn5h6Nf4HxW2WKwZfAS
vG4tlIlrjRh8LINu/Fd/XRCWmRe9AfUDHfgQe+iS7vG/nJ8lYMwojlXzOmyYOvPh
H9rxaKXpWmsoB9CzYIRgrEcBdpkzBHtM6D9fhpREgl05zI+eJlfbifuvfzEztHVi
1JkjageF3LsIkoV4uc2EWFtaYGsf3F8ceBnmgAg75Fl+Z402J/PglPnsMUuTcWRx
HIaLTUIKZVIh088J/sVHb9FFvki7com6UMbJ6WIVSL8JRVTfmb4=
=3qWQ
-----END PGP SIGNATURE-----


Reply to: