Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 41: Advisory FEDORA-2024-157678aad0 critical: python-waitress DoS

fedora
Calendar Grey November 16, 2024
Dist Fedora Esm H88
Fedora 41 announces an upgrade for python-waitress 3.0.1, addressing severe race conditions and optimizing performance, thereby boosting security.
Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

Summary

Waitress is a production-quality pure-Python WSGI server with very acceptable

performance. It has no dependencies except ones which live in the Python

standard library.

Update Information:

Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

Change Log

* Thu Nov 7 2024 Carl George - 3.0.1-1 - Update to version 3.0.1 rhbz#2322297 - Resolves: CVE-2024-49768 - Resolves: CVE-2024-49769

References


[ 1 ] Bug #2322297 - python-waitress-3.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2322297 [ 2 ] Bug #2324285 - CVE-2024-49768 python-waitress: request processing race condition in HTTP pipelining with invalid first request [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2324285 [ 3 ] Bug #2324286 - CVE-2024-49769 python-waitress: Waitress has a denial of service leading to high CPU usage/resource exhaustion [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2324286

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-157678aad0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-waitress
Product: Fedora 41
Version: 3.0.1
Release: 1.fc41
Summary: Waitress WSGI server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here