USN-2531-1: Requests vulnerability
16 March 2015
Requests could be made to expose cookies over the network.
- requests - elegant and simple HTTP library for Python
Matthew Daley discovered that Requests incorrectly handled cookies without
host values when being redirected. A remote attacker could possibly use
this issue to perform session fixation or cookie stealing attacks.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.