Files
buildroot/package
Matt Weber 25bda2ef0a package/python-twisted: Fix several request smuggling attacks
CVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting
vulnerability. When presented with two content-length headers, it
ignored the first header. When the second content-length value was
set to zero, the request body was interpreted as a pipelined request.

CVE-2020-10109
In Twisted Web through 19.10.0, there was an HTTP request splitting
vulnerability. When presented with a content-length and a chunked
encoding header, the content-length took precedence and the remainder
of the request body was interpreted as a pipelined request.

Signed-off-by: Matthew Weber <matthew.weber@rockwellcollins.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2020-07-22 23:11:12 +02:00
..
2020-07-22 13:37:14 +02:00
2020-02-25 23:24:34 +01:00
2020-02-23 09:45:10 +01:00
2020-04-25 09:06:09 +02:00
2020-02-29 23:17:29 +01:00
2020-02-29 19:26:38 +01:00
2020-05-10 22:39:00 +02:00
2020-06-02 08:41:08 +02:00
2020-07-20 21:56:41 +02:00
2020-05-08 11:39:03 +02:00
2020-07-22 13:47:00 +02:00
2020-05-08 12:08:05 +02:00
2020-07-22 11:08:12 +02:00
2020-02-11 23:28:26 +01:00
2020-04-07 21:04:41 +02:00
2020-04-07 20:28:05 +02:00
2020-07-13 08:37:19 +02:00
2020-07-22 13:44:19 +02:00
2020-05-31 23:21:38 +02:00
2020-02-23 09:26:10 +01:00
2020-07-22 09:00:59 +02:00
2020-04-08 16:30:36 +02:00
2020-05-08 09:13:34 +02:00
2020-02-15 12:04:49 +01:00
2020-07-15 23:21:34 +02:00
2020-02-15 11:58:38 +01:00
2020-04-30 14:42:03 +02:00
2020-04-29 23:49:57 +02:00
2020-02-14 09:13:07 +01:00
2020-06-02 15:16:04 +02:00
2020-07-21 07:57:28 +02:00
2020-03-08 09:41:44 +01:00
2020-05-31 23:20:15 +02:00
2020-03-07 22:43:55 +01:00
2020-04-07 20:24:58 +02:00
2020-07-22 13:44:19 +02:00
2020-03-02 23:33:57 +01:00
2020-03-07 22:52:02 +01:00
2020-02-14 09:13:07 +01:00
2020-04-07 21:02:37 +02:00
2020-05-09 09:20:45 +02:00