Fix CVE-2021-33503: An issue was discovered in urllib3 before 1.26.5.
When provided with a URL containing many @ characters in the authority
component, the authority regular expression exhibits catastrophic
backtracking, causing a denial of service if a URL were passed as a
parameter or redirected to via an HTTP redirect.
https://github.com/urllib3/urllib3/blob/1.26.6/CHANGES.rst
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit 56a105f9fb
)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
6 lines
333 B
Plaintext
6 lines
333 B
Plaintext
# md5, sha256 from https://pypi.org/pypi/urllib3/json
|
|
md5 3a88ec3bcb761ca23df2c3583949be37 urllib3-1.26.6.tar.gz
|
|
sha256 f57b4c16c62fa2760b7e3d97c35b255512fb6b59a259730f36ba32ce9f8e342f urllib3-1.26.6.tar.gz
|
|
# Locally computed sha256 checksums
|
|
sha256 c37bf186e27cf9dbe9619e55edfe3cea7b30091ceb3da63c7dacbe0e6d77907b LICENSE.txt
|