Updated python-tornado package fixes security vulnerability
Publication date: 11 Dec 2016Modification date: 11 Dec 2016
Type: security
Affected Mageia releases : 5
Description
A difference in cookie parsing between Tornado and web browsers (especially when combined with Google Analytics) could allow an attacker to set arbitrary cookies and bypass XSRF protection. The cookie parser has been rewritten to fix this attack.
References
SRPMS
5/core
- python-tornado-3.2.2-4.2.mga5