QID 174724

Date Published: 2021-04-19

QID 174724: SUSE Enterprise Linux Security update for python-waitress (SUSE-SU-2020:3269-1)



This update for python-waitress to 1.4.3 fixes the following security
issues:

- CVE-2019-16785: HTTP request smuggling through LF vs CRLF handling
(bsc#1161088).
- CVE-2019-16786: HTTP request smuggling through invalid Transfer-Encoding
(bsc#1161089).
- CVE-2019-16789: HTTP request smuggling through invalid whitespace
characters (bsc#1160790).
- CVE-2019-16792: HTTP request smuggling by sending the Content-Length
header twice (bsc#1161670).


Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: https://lists.suse.com/pipermail/sle-security-updates/2020-November/007743.html to address this issue and obtain further details.

    CVEs related to QID 174724

    Software Advisories
    Advisory ID Software Component Link