Ubuntu: 1948-1: httplib2 vulnerability
Posted by Benjamin D. Thomas   
Ubuntu Fraudulent security certificates could allow sensitive information tobe exposed when accessing the Internet.
Ubuntu Security Notice USN-1948-1
September 09, 2013

python-httplib2 vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS


Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.

Software Description:
- python-httplib2: comprehensive HTTP client library written for Python


It was discovered that httplib2 only validated SSL certificates on the
first request to a connection, and didn't report validation failures on
subsequent requests. If a remote attacker were able to perform a
man-in-the-middle attack, this flaw could possibly be exploited in certain
scenarios to alter or compromise confidential information in applications
that used the httplib2 library.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  python-httplib2                 0.7.7-1ubuntu0.1

Ubuntu 12.10:
  python-httplib2                 0.7.4-2ubuntu0.1

Ubuntu 12.04 LTS:
  python-httplib2                 0.7.2-1ubuntu2.1

Ubuntu 10.04 LTS:
  python-httplib2                 0.7.2-1ubuntu2~

In general, a standard system update will make all the necessary changes.


Package Information: