Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 11: DLA-3996-1 critical: gunicorn HTTP request smuggling

HTTP Request Smuggling has been fixed in the Python WSGI HTTP Server Gunicorn. For Debian 11 bullseye, this problem has been fixed in version 20.1.0-1+deb11u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3996-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk December 20, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gunicorn Version : 20.1.0-1+deb11u1 CVE ID : CVE-2024-1135 Debian Bug : 1069126 HTTP Request Smuggling has been fixed in the Python WSGI HTTP Server Gunicorn. For Debian 11 bullseye, this problem has been fixed in version 20.1.0-1+deb11u1. We recommend that you upgrade your gunicorn packages. For the detailed security status of gunicorn please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gunicorn Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update your Debian 11 system and enhance Gunicorn's security by following the steps outlined: update package list, upgrade Gunicorn, verify installation, and restart your application. gunicorn, debian, HTTP request smuggling, security update, server. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 20, 2024 Critical Debian LTS
197

Debian 10 Buster: DLA-3851-1 Critical Gunicorn Request Smuggling

Gunicorn, an event-based HTTP/WSGI server, fails to properly validate Transfer- Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3851-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 30, 2024 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : gunicorn Version : 19.9.0-1+deb10u1 CVE ID : CVE-2024-1135 Debian Bug : 1069126 Gunicorn, an event-based HTTP/WSGI server, fails to properly validate Transfer- Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn’s handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure. For Debian 10 buster, this problem has been fixed in version 19.9.0-1+deb10u1. We recommend that you upgrade your gunicorn packages. For the detailed security status of gunicorn please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gunicorn Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3852-2 pertains to vulnerabilities in flask. Users areadvised to apply updates to ensure system safety.. Gunicorn, HTTP Server, Request Smuggling, Security Update, Debian. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 30, 2024 Critical Debian LTS
87

Debian: DSA-4186-1 Critical: Gunicorn HTTP Response Split Fix

It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4186-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 28, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gunicorn CVE ID : CVE-2018-1000164 It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed in version 19.0-1+deb8u1. We recommend that you upgrade your gunicorn packages. For the detailed security status of gunicorn please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gunicorn Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Gunicorn, a Python WSGI HTTP server, has vulnerabilities related to HTTP response splitting. This can expose applications to various attacks, necessitating immediate upgrades.. Gunicorn Security Update, Debian Security Advisory, HTTP Response Splitting. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2018 Critical Debian
197

Debian 7: DLA-1357-1 Critical Advisory: Gunicorn Header Exploit

It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers. . Package : gunicorn Version : 0.14.5-3+deb7u2 CVE ID : CVE-2018-1000164 Debian Bug : #896548 It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers. For more information and background, please see: For Debian 7 "Wheezy", this issue has been fixed in gunicorn version 0.14.5-3+deb7u2. We recommend that you upgrade your gunicorn packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Explore a new security patch for gunicorn on Debian 7 aimed at mitigating header injection vulnerabilities along with suggested remedial actions.. gunicorn security update, Debian LTS, attack mitigation, http server vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 22, 2018 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here