Description
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 pypi | | =0.2 || =1.0 || =1.1 || =1.1.1 || =1.2 || =1.2.1 || =2.0 || =2.1 || =2.1.1 || =2.2 || =2.2.1 || =2.3 || =2.4 || =2.4.1 || =3.0 || =3.0.1 || =3.0.2 || =3.1 || =3.1.1 || =3.2 || =3.2.1 || =3.2.2 || =4.0 || =4.0.1 || =4.0.2 || =4.1 || =4.1b2 || =4.2 || =4.2.1 || =4.2b1 || =4.3 || =4.3b1 || =4.3b2 || =4.4 || =4.4.1 || =4.4.2 || =4.4.3 || =4.4b1 || =4.5 || =4.5.1 || =4.5.2 || =4.5.3 || =4.5b1 || =4.5b2 || =5.0 || =5.0.1 || =5.0.2 || =5.0a1 || =5.0b1 || =5.1 || =5.1.1 || =5.1b1 || =6.0 || =6.0.1 || =6.0.2 || =6.0.3 || =6.0.4 || =6.0a1 || =6.0b1 || =6.1 || =6.1b1 || =6.1b2 || =6.2 || =6.2b1 || =6.2b2 || =6.3 || =6.3.1 || =6.3.2 || =6.3.3 || =6.3b1 || =6.4 || =6.4.1 || =6.4.2 || =6.4b1 || =6.5 || =6.5.1 || =6.5.2 || =6.5.3 || =6.5.4 || =6.5.5 || =6.5.6 || =6.5.7 || =6.5b1 || >=0 <6.5.8 | 6.5.8 |
 rpm rhel9 | | - | - |
 rpm rhel10 | | - | - |
 debian 12 | | =6.2.0-3 || =6.2.0-3+deb12u1 || =6.2.0-3+deb12u2 || =6.2.0-3+deb12u3 || =6.2.0-3+deb12u4 || =6.3.2-1 || =6.4.0-1 || =6.4.0-2 || =6.4.1-1 || =6.4.1-2 || =6.4.1-3 || =6.4.2-1 || =6.4.2-2 || =6.4.2-3 || =6.5.2-1 || =6.5.2-2 || =6.5.2-3 || =6.5.4-0.1 || =6.5.4-1 || =6.5.5-1 || =6.5.5-2 || =6.5.5-3 || =6.5.5-4 || =6.5.5-5 | - |
 debian 13 | | =6.4.2-3 || =6.4.2-3+deb13u1 || =6.4.2-3+deb13u2 || =6.5.2-1 || =6.5.2-2 || =6.5.2-3 || =6.5.4-0.1 || =6.5.4-1 || =6.5.5-1 || =6.5.5-2 || =6.5.5-3 || =6.5.5-4 || =6.5.5-5 | - |
 debian 14 | | =6.4.2-3 || =6.5.2-1 || =6.5.2-2 || =6.5.2-3 || =6.5.4-0.1 || =6.5.4-1 || =6.5.5-1 || =6.5.5-2 || =6.5.5-3 || =6.5.5-4 || =6.5.5-5 | - |
 rpm rhel10 | | - | - |
 rpm rhel9 | | - | - |
 rpm rhel8 | | - | - |
 rpm rhel10 | | - | - |