Updated python-httplib2 packages fix a security vulnerability
Publication date: 12 Mar 2021Modification date: 12 Mar 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-21240
Description
A malicious server which responds with long series of \xa0 characters in the www-authenticate header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server (CVE-2021-21240).
References
SRPMS
7/core
- python-httplib2-0.19.0-1.mga7
8/core
- python-httplib2-0.19.0-1.mga8