mirror of
https://github.com/godotengine/buildroot.git
synced 2026-01-01 13:49:03 +03:00
"\r\n" sequences were not properly filtered when handling redirections.
This allowed an attacker to perform CRLF attacks such as HTTP header
injection:
https://github.com/bottlepy/bottle/issues/913
Python-bottle now uses setuptools instead of distutils.
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit aa64e33c51)
4 lines
232 B
Plaintext
4 lines
232 B
Plaintext
# md5 from https://pypi.python.org/pypi/bottle/json, sha256 locally computed
|
|
md5 6c38912f4755ba71d852fbe320bdd61c bottle-0.12.11.tar.gz
|
|
sha256 a1958f9725042a9809ebe33d7eadf90d1d563a8bdd6ce5f01849bff7e941a731 bottle-0.12.11.tar.gz
|