UbuntuUpdates.org

Package "python-tornado-doc"

Name: python-tornado-doc

Description:

scalable, non-blocking web server and tools - documentation

Latest version: 6.4.0-1ubuntu0.1
Release: noble (24.04)
Level: updates
Repository: main
Head package: python-tornado
Homepage: https://www.tornadoweb.org/

Links


Download "python-tornado-doc"


Other versions of "python-tornado-doc" in Noble

Repository Area Version
base main 6.4.0-1build1
security main 6.4.0-1ubuntu0.1

Changelog

Version: 6.4.0-1ubuntu0.1 2024-12-11 16:06:46 UTC

  python-tornado (6.4.0-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: Cookie header denial of service.
    - debian/patches/CVE-2024-52804.patch: Replace algorithm in _OctalPatt,
      _QuotePatt, and _nulljoin with _unquote_sub in tornado/httputil.py. Add
      tests.
    - CVE-2024-52804

 -- Hlib Korzhynskyy <email address hidden> Thu, 28 Nov 2024 16:53:42 -0330

CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2



About   -   Send Feedback to @ubuntu_updates