{
  "schema_version": "1.7.0",
  "id": "MGASA-2016-0418",
  "published": "2016-12-11T22:44:05Z",
  "modified": "2016-12-11T22:34:08Z",
  "summary": "Updated python-tornado package fixes security vulnerability",
  "details": "A difference in cookie parsing between Tornado and web browsers\n(especially when combined with Google Analytics) could allow an attacker\nto set arbitrary cookies and bypass XSRF protection. The cookie parser\nhas been rewritten to fix this attack.\n",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2016-0418.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=19859"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PJEFGW4II3TYTO7TICVK47WENL2URP46/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:5",
        "name": "python-tornado",
        "purl": "pkg:rpm/mageia/python-tornado?arch=source&distro=mageia-5"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.2.2-4.2.mga5"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
