MGASA-2015-0251

Source
https://advisories.mageia.org/MGASA-2015-0251.html
Import Source
https://advisories.mageia.org/MGASA-2015-0251.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0251
Related
Published
2015-07-01T12:40:22Z
Modified
2015-07-01T12:27:47Z
Summary
Updated python-tornado package fixes security vulnerability
Details

Security fixes (CVE-2014-9720) The XSRF token is now encoded with a random mask on each request. This makes it safe to include in compressed pages without being vulnerable to the BREACH attack. This applies to most applications that use both the xsrf_cookies and gzip options (or have gzip applied by a proxy).

References
Credits

Affected packages

Mageia:4 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/mageia/python-tornado?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1-4.1.mga4

Ecosystem specific

{
    "section": "core"
}