-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 21 Dec 2024 15:28:17 +0100 Source: python-urllib3 Binary: python3-urllib3 Architecture: all Version: 1.26.12-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Guilhem Moulin Description: python3-urllib3 - HTTP library with thread-safe connection pooling for Python3 Closes: 1053626 1054226 1074149 1089507 Changes: python-urllib3 (1.26.12-1+deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Fix CVE-2023-43804: Cookie request header isn't stripped during cross-origin redirects. (Closes: #1053626) * Fix CVE-2023-45803: Request body not stripped after redirect from 303 status changes request method to GET. (Closes: #1054226) * Fix CVE-2024-37891: Proxy-Authorization request header isn't stripped during cross-origin redirects. (Closes: #1074149) * Use system 'six' module in urllib3.util.ssltransport. (Closes: #1089507) * Fix test/test_connectionpool.py (currently ignored). * Adjust d/salsa-ci.yml for bookworm. * Adjust d/gbp.conf for bookworm. Checksums-Sha1: 6b41fcc8af1e64aae69611ae95ed456f0ae0994a 6972 python-urllib3_1.26.12-1+deb12u1_all-buildd.buildinfo 7da47c3963f5785bcfc17e7633823a4365a5532d 113580 python3-urllib3_1.26.12-1+deb12u1_all.deb Checksums-Sha256: 4539ae01d7332b725453681c2a11b8624fafd3f13e8f6d1462336a7b09cd1d1c 6972 python-urllib3_1.26.12-1+deb12u1_all-buildd.buildinfo e4ad7b9298d0dfbf206440a20cc925f6db6d581398c9b3f63eb660226a3edd17 113580 python3-urllib3_1.26.12-1+deb12u1_all.deb Files: fc5886649a3b8008088b05b6d0594557 6972 python optional python-urllib3_1.26.12-1+deb12u1_all-buildd.buildinfo 0e71ad1f2873e479a73bb5e4d742117d 113580 python optional python3-urllib3_1.26.12-1+deb12u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzcbx6nIE/ydHa1FFigL77i1GSVkFAmd4MOIACgkQigL77i1G SVnOzQ//XR5DFs4ng5FyPCx1E36hBZZVOEdhnuq/pkXRn9ZcDTvwsiGxOC5RUAxw tsBtqaYDLGsVyHbVspahjmcXszOz7OxeOj+kbQhEywe9d4/Ez2U+0S7EkvDh+goG nvVvZ5uVSKvdv0Blor/cP3q/HQu0nUbVL5YtO56MMRehUHbufIM0NMJBrJEyVM25 njgNW1RcNJ+kD8HLNjoXoOQVQMwOJhU8by2K6uQxkJXGbvd2s09uj5JYORC5am+9 zkHkir/M1pCcDyzbODJuhkJZMHnF7FKOs0PO+jzNAngfQrvtaNOL8hAcZ97T4Tiw fC4TCJVRkpZl7HbLkSuz6gSEHlV+zVwl4WHIq/dex6EaWL6YeJMh86YwuaOIVl1V c1FqPA062KehFWOAjFsfirnbhOaiiEmUqtmBmEvr+H+Z/+bPR0iW02OJgyHYfndB iAytOaY/JerkAQqKbmws4nPcrPwqWr5TuNIoHyiKJPV9AznpS6tYLTaT5VhMEdqz GvsZ0+ywyYDEIgVB85x+0QgQtJzR9kunUZrEzPpyRYpDfg6ZEx9wNTqsT6Fh9ae/ z35wSO4BK1Zq1FZHYjIRh9hXiQtzv8QyujPZNoIrHdPxwiz06bmwINN2fPwyIhaV ivNCtT+qmvB/3Xf2Yqckd/hclZHcx89H+b82pjRaoOGIgvD7KGY= =jtGd -----END PGP SIGNATURE-----