Vulnerability Bulletins

DSA-3743 python-bottle - security update

   
Affected software Debian
 
It was discovered that bottle, a WSGI-framework for the Pythonprogramming language, did not properly filter "
" sequences whenhandling redirections. This allowed an attacker to perform CRLFattacks such as HTTP header injection.

More info:

https://www.debian.org/security/2016/dsa-3743