Ubuntu Security Notice 1948-1 – It was discovered that httplib2 only validated SSL certificates on the first request to a connection, and didn’t report validation failures on subsequent requests. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could possibly be exploited in certain scenarios to alter or compromise confidential information in applications that used the httplib2 library…. Ubuntu Security Notice 1948-1 – It was discovered that httplib2 only validated SSL certificates on the first request to a connection, and didn’t report validation failures on subsequent requests. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could possibly be exploited in certain scenarios to alter or compromise confidential information in applications that used the httplib2 library.

Read more http://packetstormsecurity.com/files/123146/USN-1948-1.txt