Advisories ยป MGASA-2016-0418

Updated python-tornado package fixes security vulnerability

Publication date: 11 Dec 2016
Type: security
Affected Mageia releases : 5

Description

A difference in cookie parsing between Tornado and web browsers
(especially when combined with Google Analytics) could allow an attacker
to set arbitrary cookies and bypass XSRF protection. The cookie parser
has been rewritten to fix this attack.
                

References

SRPMS

5/core