Cédric Krier has found that trytond, the Tryton application server, accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3853-1
"Edbo" and Cedric Krier discovered that the Tryton application server does enforce record rules when only reading fields without an SQL type (like Function fields). . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3547-1
Two vulnerabilities have been discovered in the server for the Tryton application platform, which may result in information disclosure of password hashes or file contents. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3656-1
It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2444-1
Get the latest Linux and open source security news straight to your inbox.