[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3743-1 python-bottle -- python-bottle

ID: oval:org.secpod.oval:def:602706Date: (C)2016-12-21   (M)2023-04-19
Class: PATCHFamily: unix




It was discovered that bottle, a WSGI-framework for the Python programming language, did not properly filter "\r\n" sequences when handling redirections. This allowed an attacker to perform CRLF attacks such as HTTP header injection.

Platform:
Debian 8.x
Product:
python-bottle
Reference:
DSA-3743-1
CVE-2016-9964
CVE    1
CVE-2016-9964
CPE    2
cpe:/o:debian:debian_linux:8.x
cpe:/a:bottlepy:python-bottle

© SecPod Technologies