Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clarify affected versions re: 4.4.2 security fix #1865

Closed
dol-sen opened this issue Oct 23, 2016 · 1 comment
Closed

Clarify affected versions re: 4.4.2 security fix #1865

dol-sen opened this issue Oct 23, 2016 · 1 comment

Comments

@dol-sen
Copy link

dol-sen commented Oct 23, 2016

The release notes are not clear which versions are vulnerable for the cookie parser security fix.

quote: (older versions of Tornado would reject the entire header for a single invalid cookie)

Does that infer that only previous 4.4 releases were vulnerable? What about 4.2 and 4.3 releases, are any of those vulnerable? older...?

As a package maintainer, but not a tornado coder, I need to know the extent of the vulnerability. If I need to fastrack stabilization of the 4.4.2 release and remove which older versions, etc...

https://bugs.gentoo.org/show_bug.cgi?id=597740

Thank you.
Brian

@bdarnell
Copy link
Member

bdarnell commented Nov 4, 2016

Sorry for the slow response. I believe all prior versions are vulnerable; this is not specific to the 4.4 or even the 4.x series.

@bdarnell bdarnell closed this as completed Nov 4, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants