security advisorymoderatedebian
It was discovered that Bottle, a WSGI-framework for Python, performed a too permissive detection of JSON content, resulting a potential bypass of security mechanisms. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2948-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 04, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-bottle CVE ID : CVE-2014-3137 It was discovered that Bottle, a WSGI-framework for Python, performed a too permissive detection of JSON content, resulting a potential bypass of security mechanisms. For the stable distribution (wheezy), this problem has been fixed in version 0.10.11-1+deb7u1. For the testing distribution (jessie), this problem has been fixed in version 0.12.6-1. For the unstable distribution (sid), this problem has been fixed in version 0.12.6-1. We recommend that you upgrade your python-bottle packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover a recent security patch for python-bottle in Debian that mitigates possible vulnerabilities related to security circumvention.. Python-Bottle Security, Debian Update, JSON Bypass, WSGI Framework. . LinuxSecurity.com Team
Jun 04, 2014
Debian