openSUSE-SU-2019:0159-1: moderate: Security update for python-urllib3

openSUSE Security Update: Security update for python-urllib3

Announcement ID: openSUSE-SU-2019:0159-1
Rating: moderate
References: #1024540 #1074247 #1110422
Cross-References: CVE-2016-9015
Affected Products:
openSUSE Leap 42.3

An update that solves one vulnerability and has two fixes
is now available.


This update for python-urllib3 fixes the following issues:

python-urllib3 was updated to version 1.22 (fate#326733, bsc#1110422) and
contains new features and lots of bugfixes:

The full changelog can be found on:

Security issues fixed:

– CVE-2016-9015: TLS certificate validation vulnerability (bsc#1024540).
(This issue did not affect our previous version 1.16.)

Non security issues fixed:

– bsc#1074247: Fix test suite, use correct date (gh#shazow/urllib3#1303).

This update was imported from the SUSE:SLE-12-SP1:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

– openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-159=1

Package List:

– openSUSE Leap 42.3 (noarch):



To unsubscribe, e-mail:
For additional commands, e-mail: