LWN.net Logo

python-cherrypy: unauthorized file access via malicious cookie

Package(s):python-cherrypy CVE #(s):CVE-2008-0252
Created:January 9, 2008 Updated:February 6, 2008
Description:

From the Fedora advisory:

Malicious cookies may allow access to files outside the session directory.

Alerts:
Debian DSA-1481-1 2008-02-05
Gentoo 200801-11 2008-01-27
rPath rPSA-2008-0030-1 2008-01-24
Fedora FEDORA-2008-0333 2008-01-07
Fedora FEDORA-2008-0299 2008-01-07

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds