Early Access — Mondoo Vulnerability Intelligence is currently in preview.
This update for python-tornado6 fixes the following issues:
reason argument used in HTTP headers and in HTML default error pages can be used by
attackers to launch header injection or XSS attacks (bsc#1254903).HTTPHeaders.add method can lead
to DoS when processing a maliciously crafted HTTP request (bsc#1254905)._parseparam function of httputil.py can lead to DoS
when processing maliciously crafted parameters in a Content-Disposition header (bsc#1254904).6.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.16.3.2-150400.9.12.1