You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa python-bottle

Sigurnosni nedostatak programskog paketa python-bottle

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LDE

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

– ————————————————————————-
Debian Security Advisory DSA-2948-1 security@debian.org
http://www.debian.org/security/ Moritz Muehlenhoff
June 04, 2014 http://www.debian.org/security/faq
– ————————————————————————-

Package : python-bottle
CVE ID : CVE-2014-3137

It was discovered that Bottle, a WSGI-framework for Python, performed
a too permissive detection of JSON content, resulting a potential
bypass of security mechanisms.

For the stable distribution (wheezy), this problem has been fixed in
version 0.10.11-1+deb7u1.

For the testing distribution (jessie), this problem has been fixed in
version 0.12.6-1.

For the unstable distribution (sid), this problem has been fixed in
version 0.12.6-1.

We recommend that you upgrade your python-bottle packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJTj0HbAAoJEBDCk7bDfE425ToQAKVd+qzgQWMPgKahLtlDz9fF
yAN5GG6HcxT9G5TGmTOQ2kundqezmJw2Y/slO8tBJsh8YJDuGXLwqcbpbVj9kLXb
X+oYPzARSUUy/HOpVXuD0cy/7713typ85cFC4j2IONl+uqLc1rFD8EikIc1MZQg2
yYKCb/PvE3wwS2Ctko2ODsTTO2VDjzl4Qr14dZUJokbJD6mr0MfxF7ijeygcpLaL
wSh6KF6fNnfBEVQg1YBn4ejTy4Ay7QXbaY42LpBMAl7C5FwnC9WI/hudS6SSmwUY
OJE2kh7fq/B8wQgdkHh61Sm12oYMSAVdWn4bGumb2Hq/I462ED47fnkfJtfIN0fq
Gswamw3eDInibZ36GeB8BG4FmCiCzQxbslmX/gJLojAFTjEIjjIT/s3YiApBPdbc
AP1w4ji2QanqhKZB9Al8xLJB7lK25XXiC/0n1rKQz8ZYW3lIgFpoy8jXWxQa+IYp
1oCS2+3Zyuub7Y6siiG6OnYEB8SbY6hP08e/igotCPSXLhhDtkCaI8VJud7U8/Ug
Ta99ZqtUVMEEije7Q/FjQqD7eyulr1N9gs/71NTkzZCMkKDcShR/eT9P6AB44hXC
CDmFYFpnBPRDjsP5kTOem/nl1iacivZ4FpS5vy+VaRlE2BDYSc6LfXlcBBZT7jp5
TupqBW30QP5WGjICLw72
=MKdR
—–END PGP SIGNATURE—–


To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of “unsubscribe”. Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20140604155906.GB2894@pisco.westfalen.local

AutorMarijo Plepelic
Cert idNCERT-REF-2014-06-0013-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa chkrootkit

Otkriven je sigurnosni nedostatak u programskom paketu chkrootkit. Otkriveni nedostatak potencijalnim lokalnim napadačima omogućuje pokretanje proizvoljnog programskog koda i stjecanje...

Close