Comment 2 for bug 1898078

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package python2.7 - 2.7.17-1~18.04ubuntu1.2

---------------
python2.7 (2.7.17-1~18.04ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: CRLF injection
    - debian/patches/CVE-2020-26116.patch: prevent header injection
      in http methods in Lib/httplib.py, Lib/test/test_httlib.py.
    - CVE-2020-26116
  * debian/patches/issue9146.patch: re-adding fix FIPS mode environments where MD5
    isn't available in Modules/_hashopenssl.c. (LP: #1898078)

 -- <email address hidden> (Leonidas S. Barbosa) Wed, 30 Sep 2020 10:38:04 -0300