Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian: DSA-4186-1 Critical: Gunicorn HTTP Response Split Fix

debian
Calendar Grey April 28, 2018
Debian Logo
Gunicorn, a Python WSGI HTTP server, has vulnerabilities related to HTTP response splitting. This can expose applications to various attacks, necessitating immediate upgrades.
It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting

Summary

It was discovered that gunicorn, an event-based HTTP/WSGI server was
susceptible to HTTP Response splitting.

For the oldstable distribution (jessie), this problem has been fixed
in version 19.0-1+deb8u1.

We recommend that you upgrade your gunicorn packages.

For the detailed security status of gunicorn please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gunicorn

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: gunicorn
CVE ID: CVE-2018-1000164

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here