Wind River Support Network

HomeDefectsLIN1019-5485
Fixed

LIN1019-5485 : Security Advisory - python-urllib3 - CVE-2020-26137

Created: Oct 11, 2020    Updated: Nov 19, 2020
Resolved Date: Oct 26, 2020
Found In Version: 10.19.45.1
Fix Version: 10.19.45.13
Severity: Standard
Applicable for: Wind River Linux LTS 19
Component/s: Userspace

Description

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CREATE(Triage):(User=admin) [CVE-2020-26137|https://nvd.nist.gov/vuln/detail/CVE-2020-26137]

CVEs


Live chat
Online