Improper resource allocation In tornado
Description
Tornado has an HTTP cookie parsing DoS vulnerability The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests.
See also CVE-2024-7592 for a similar vulnerability in cpython.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 6.2.0-3+deb12u1 | ||
debian 13 | 6.4.2-1 | ||
debian 14 | 6.4.2-1 | ||
pypi | 6.4.2 | ||
rpm rhel9.2 | 0:0.11.4-7.el9_2.4 | ||
rpm rhel8 | 0:0.10.18-2.el8_10.4 | ||
rpm rhel7 | - | - | |
rpm rhel8.8 | 0:0.10.15-4.el8_8.4 | ||
rpm rhel9 | 0:0.11.8-1.el9_5.2 | ||
rpm rhel9.4 | 0:0.11.7-2.el9_4.3 |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2.