-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: python-waitress security update Advisory ID: RHSA-2020:0720-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:0720 Issue date: 2020-03-05 CVE Names: CVE-2019-16785 CVE-2019-16786 CVE-2019-16789 ==================================================================== 1. Summary: An update for python-waitress is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 15.0 - noarch 3. Description: Waitress is a pure Python WSGI server which supports HTTP/1.0 and HTTP/1.1. Security Fix(es): * HTTP request smuggling through LF vs CRLF handling (CVE-2019-16785) * HTTP request smuggling through invalid Transfer-Encoding (CVE-2019-16786) * HTTP Request Smuggling through Invalid whitespace characters in headers(CVE-2019-16789) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1789807 - CVE-2019-16789 waitress: HTTP Request Smuggling through Invalid whitespace characters in headers1791415 - CVE-2019-16786 waitress: HTTP request smuggling through invalid Transfer-Encoding 1791420 - CVE-2019-16785 waitress: HTTP request smuggling through LF vs CRLF handling 6. Package List: Red Hat OpenStack Platform 15.0: Source: python-waitress-1.4.2-1.el8ost.src.rpm noarch: python3-waitress-1.4.2-1.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-16785 https://access.redhat.com/security/cve/CVE-2019-16786 https://access.redhat.com/security/cve/CVE-2019-16789 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXmDpV9zjgjWX9erEAQgjXw//fIr4EOEk/pcPXAuBgwojaU0qXwydf6dN XBexqIcvU5YbFTD1tplF/D2jR1c56RyHjlGL8vTeQJBLugpctebi7JwFhlNxtlz2 RJUWXsoIEqlP3UGRzT8BmVKi8S/BtR6E09hJHjfIN9/U9w5mymTFZA+vKHaJ8YuO KkkuPb7D3IhCwpL7IxCY6OXXaGr+T3El9VU102u0B3QBZzQcSczPvvwgl0sisk/Q zb4E/YCcmjSJxgiJmJFHamaJkxa+vDqhKwhAvihz5RppoEEo64iIrCFiJcjMJTyu SySR/jJm9v6Vjt7K3maUBshP7yzJXx+uzUeVmRjqRZt17HhV4+PW4UyjALYZ2p7y Hjd02aQLdRQ3nynBZN8dm6//7iKMmrx74BvrlOz2pkQ2Awwpgkm0CK0wTyc0ey7r KMXmMHspntQD/xXcWlgqBOHMNXdWNEO9brEGB8yEdhSbmSp9ABaEXPnW3vEfJxzK RunbIzXY5tog6wt1/ASEuCTN70KbzP61oNJQiaIX4dRaPh9iauqcHrd+l4Tscxa9 Bwjy4JQenvohPe1MjDxXZnJYpgBTg92Is5JZ/P1c3L2mGCVmVfWsOZSknW+BK+qV E0DFNDjH9PBB5pGy3OdA8wQIAdgkppmuOZ0JLF5nDL3fdlazKDAi81nzHaNFHRMj SwPKW/M4egE=6UYQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Waitress is a pure Python WSGI server which supports HTTP/1.0 and HTTP/1.1.
Security Fix(es):
* HTTP request smuggling through LF vs CRLF handling (CVE-2019-16785)
* HTTP request smuggling through invalid Transfer-Encoding (CVE-2019-16786)
* HTTP Request Smuggling through Invalid whitespace characters in headers(CVE-2019-16789)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
https://access.redhat.com/security/cve/CVE-2019-16785 https://access.redhat.com/security/cve/CVE-2019-16786 https://access.redhat.com/security/cve/CVE-2019-16789 https://access.redhat.com/security/updates/classification#low
Red Hat OpenStack Platform 15.0:
Source:
python-waitress-1.4.2-1.el8ost.src.rpm
noarch:
python3-waitress-1.4.2-1.el8ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key
An update for python-waitress is now available for Red Hat OpenStackPlatform 15 (Stein).Red Hat Product Security has rated this update as having a security impactof Low. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat OpenStack Platform 15.0 - noarch
1789807 - CVE-2019-16789 waitress: HTTP Request Smuggling through Invalid whitespace characters in headers1791415 - CVE-2019-16786 waitress: HTTP request smuggling through invalid Transfer-Encoding
1791420 - CVE-2019-16785 waitress: HTTP request smuggling through LF vs CRLF handling
Get the latest Linux and open source security news straight to your inbox.