LWN.net Logo

python-tornado: HTTP header injection

Package(s):python-tornado CVE #(s):CVE-2012-2374
Created:May 29, 2012 Updated:June 18, 2012
Description: From the CVE entry:

CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.

Alerts:
Fedora FEDORA-2012-8194 2012-05-29
Fedora FEDORA-2012-8217 2012-05-29
Fedora FEDORA-2012-8205 2012-05-29
openSUSE openSUSE-SU-2012:0755-1 2012-06-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds