VDB
GCVE-110-MAGEIA-2020-83
GCVE-110-MAGEIA-2020-83
Advisory Published
Updated python-waitress packages fix security vulnerabilities:
If a front-end server does not parse header fields with an LF the same
way as it does those with a CRLF it can lead to the front-end and the
back-end server parsing the same HTTP message in two different ways.
This can lead to a potential for HTTP request smuggling/splitting whereby
Waitress may see two requests while the front-end server only sees a
single HTTP message (CVE-2019-16785).
Waitress through version 1.3.1 would parse the Transfer-Encoding header
and only look for a single string value, if that value was not chunked
it would fall through and use the Content-Length header instead. This
could allow for Waitress to treat a single request as multiple requests
in the case of HTTP pipelining (CVE-2019-16786).
In Waitress through version 1.4.0, if a proxy server is used in front of
waitress, an invalid request may be sent by an attacker that bypasses the
front-end and is parsed differently by waitress leading to a potential for
HTTP request smuggling. If a front-end server does HTTP pipelining to a
backend Waitress server this could lead to HTTP request splitting which
may lead to potential cache poisoning or unexpected information disclosure
(CVE-2019-16789).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | efl | 0 (affected), 1.22.2-1.1.mga7 (unaffected) | — |
| Mageia | bullet | 0 (affected), 2.89-1.mga7 (unaffected) | — |
| Mageia | openmw | 0 (affected), 0.45.0-1.1.mga7 (unaffected) | — |
| Mageia | irrlamb | 0 (affected), 0.2.1-1.20160920.8.mga7 (unaffected) | — |
| Mageia | panda3d | 0 (affected), 1.10.2-1.1.mga7 (unaffected) | — |
| Mageia | stuntrally | 0 (affected), 2.6.1-1.1.mga7 (unaffected) | — |
| Mageia | vdrift | 0 (affected), 20141020-8.1.mga7 (unaffected) | — |
| Mageia | stuntrally-tracks | 0 (affected), 2.6.1-1.mga7 (unaffected) | — |
| Mageia | python-waitress | 1.4.2-1.mga7 (unaffected), 0 (affected), 0 (affected), 1.4.2-1.mga7 (unaffected) | — |
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.