-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 21 Dec 2024 15:28:17 +0100 Source: python-urllib3 Architecture: source Version: 1.26.12-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian Python Team Changed-By: Guilhem Moulin Closes: 1053626 1054226 1074149 1089507 Changes: python-urllib3 (1.26.12-1+deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * Fix CVE-2023-43804: Cookie request header isn't stripped during cross-origin redirects. (Closes: #1053626) * Fix CVE-2023-45803: Request body not stripped after redirect from 303 status changes request method to GET. (Closes: #1054226) * Fix CVE-2024-37891: Proxy-Authorization request header isn't stripped during cross-origin redirects. (Closes: #1074149) * Use system 'six' module in urllib3.util.ssltransport. (Closes: #1089507) * Fix test/test_connectionpool.py (currently ignored). * Adjust d/salsa-ci.yml for bookworm. * Adjust d/gbp.conf for bookworm. Checksums-Sha1: 08eb63f131adf196ba857c24f8840b943c6b8f59 2344 python-urllib3_1.26.12-1+deb12u1.dsc d6b3be6598bdb83f9e772b180cd17301c67345a8 16004 python-urllib3_1.26.12-1+deb12u1.debian.tar.xz 348e8b88cf8f44d49dd01399341576ee0c61c790 7412 python-urllib3_1.26.12-1+deb12u1_amd64.buildinfo Checksums-Sha256: c3c9eb0a71d0f63c3bb43948aa8c10ad2a64e0fade64c6299ac4f6147c585e13 2344 python-urllib3_1.26.12-1+deb12u1.dsc f556a06253aaaffa8cbe0505e49c1a6a27c7293e2f2f3bdb3fe1e6636963e729 16004 python-urllib3_1.26.12-1+deb12u1.debian.tar.xz 05d6df5de4cac0d260e8bce00ec3f7665dd0855d7c0324191d45438871281f33 7412 python-urllib3_1.26.12-1+deb12u1_amd64.buildinfo Files: d973c60dde044aaaf3637c51b1e26048 2344 python optional python-urllib3_1.26.12-1+deb12u1.dsc aae21d1f0f255578dfa99bb31b557699 16004 python optional python-urllib3_1.26.12-1+deb12u1.debian.tar.xz b2de45aed98078c2dae02305f75afa03 7412 python optional python-urllib3_1.26.12-1+deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmdm1o4ACgkQ05pJnDwh pVJ3XBAAk51mJ3sGYQr41FGE7MWY65nctnMPLYeqiIa1cTXPP1EF+nj5k6t+dyEG gxP/WJqWmNqqxhHxH+TY1DHJ5H8X60G9ltH3HjY9dkD6H1mIFp65d4KV7AuGREgI KOEArNrgXJ1qNUKBrhVyzSS0DjvMmfONKUCdADiNjDCkH7tFR+kuamDwblDtfC5T V8B/2m5uELraMTCawJl0sS88Rrsx7cZjbGSLqJVTzrnqEA0oIdcO7M92GN+KrLgi y9yf3rJVCGal8GcMffEcUFpB0/H0mQDX6Ppjw6mGOyfhCBi6+vrKyKVMRjUC7pEA BaN26kF+Reak+aHP9M1n5bQRg1YjorhJsbWCeK7LVRGcLjcRH2kDoN4z5JxTDyU+ 3UuwTxnoD45yFCQ2V3U4scA3H0mnX2yLizQTMk83L469Tmppv1TuR6hFl+mrThFF 0EiaxpoM72BK44o4tgpvBlPmdb6FpWg8pLlhFoGwZ9iAbWrmKcGSBYvuI8mE6cct +DK09OpbZuseTvsjj8XDwIEQa+qQIXB+6MYcn/IJpOM0evP4dCCZ+HqkoI+gZpzr ipMAkQ0ui1LGeH1qPu+PTKmBt9mPtGLEUfN7Kd6pm27SXDNRwLSVRK+qIsfpMZW9 Km8DYj+DlHtDfq2wFUf9Jn7ciNLv8+V/tbH7ODjrlXSV69aVI5Y= =TSID -----END PGP SIGNATURE-----