Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Mageia: 2020-0083 Moderate: Python-Waitress HTTP Request Vulnerabilities

mageia
Calendar Grey February 13, 2020
Dist Mageia Esm H88
Enhanced python-waitress plugins resolve urgent vulnerabilities in server interpretation, improving defenses against possible intrusions.
Updated python-waitress packages fix security vulnerabilities: If a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead ...

Summary

Updated python-waitress packages fix security vulnerabilities:
If a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead to the front-end and the back-end server parsing the same HTTP message in two different ways. This can lead to a potential for HTTP request smuggling/splitting whereby Waitress may see two requests while the front-end server only sees a single HTTP message (CVE-2019-16785).
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. This could allow for Waitress to treat a single request as multiple requests in the case of HTTP pipelining (CVE-2019-16786).
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a p...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=26014

- https://docs.pylonsproject.org/projects/waitress/en/latest/#security-fixes

- https://www.cve.org/CVERecord?id=CVE-2019-16785

- https://www.cve.org/CVERecord?id=CVE-2019-16786

- https://www.cve.org/CVERecord?id=CVE-2019-16789

Resolution

SRPMS

- 7/core/python-waitress-1.4.2-1.mga7

Publication date: 13 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0083.html
Type: security
CVE: CVE-2019-16785, CVE-2019-16786, CVE-2019-16789

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here