Improper resource allocation - Buffer overflow In python-tornado
Description
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 6.5.6 | ||
rpm rhel10 | - | - | |
rpm rhel7 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - | ||
rpm rhel10 | - | - |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.