[Buildroot] [PATCH] package/python-urllib3: security bump to version 1.24.2

Thomas Petazzoni thomas.petazzoni at bootlin.com
Fri Apr 26 07:14:43 UTC 2019


On Thu, 25 Apr 2019 09:07:22 +0200
Peter Korsgaard <peter at korsgaard.com> wrote:

> Fixes the following security issue:
> 
> - CVE-2019-11324: The urllib3 library before 1.24.2 for Python mishandles
>   certain cases where the desired set of CA certificates is different from
>   the OS store of CA certificates, which results in SSL connections
>   succeeding in situations where a verification failure is the correct
>   outcome.  This is related to use of the ssl_context, ca_certs, or
>   ca_certs_dir argument.
> 
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
> ---
>  package/python-urllib3/python-urllib3.hash | 4 ++--
>  package/python-urllib3/python-urllib3.mk   | 4 ++--
>  2 files changed, 4 insertions(+), 4 deletions(-)

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com


More information about the buildroot mailing list