| Summary: | python-tornado new security issue CVE-2023-28370 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, davidwhodgins, geiger.david68210, sysadmin-bugs, tarazed25 |
| Version: | 8 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA8-64-OK | ||
| Source RPM: | python-tornado-6.2-1.mga9.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2023-06-20 15:03:31 CEST
David Walser
2023-06-20 15:03:41 CEST
Status comment:
(none) =>
Fixed upstream in 6.3.2 Done for both mga8 and cauldron! freeze_move requested for cauldron. CC:
(none) =>
geiger.david68210 Many thanks; assigning to you. CC:
geiger.david68210 =>
(none) Mageia 8 update: python3-tornado-6.1-1.1.mga8 python3-tornado-doc-6.1-1.1.mga8 from python-tornado-6.1-1.1.mga8.src.rpm Status comment:
Fixed upstream in 6.3.2 =>
(none)
David GEIGER
2023-06-22 16:38:36 CEST
Assignee:
geiger.david68210 =>
qa-bugs
David Walser
2023-06-23 00:46:45 CEST
CC:
(none) =>
geiger.david68210 Mageia8, x86_64 Installed the two packages and looked for applications which need it. It seems to be aimed at web-based frameworks. Installed mopidy to try out in Firefox. Not entirely sure what I was doing but managed to get it working by using a local (user) mopidy.conf and opening port 6680. Started the server $ mopidy --config ./.mopidy.conf Entered http://<network address of host>:6680 in the address field and mopidy brought up a web page which showed iris as the web client. Clicking on that generates the menu page "Playing now" which contains various controls. I had no luck trying to play tracks from an m3u playlist. The complaint was "This appears to be a text file...." which is what it is. vlc accepts these files and displays a menu of tracks so it seems that the term "playlist" mean different things depending on who you talk to. Anyway, there is a 'browse' button which works just like any file browser and allows selection of files to play directly. That works fine and treats the current directory as a "playlist". Updated the packages and used the same config file with mopidy and iris to play tracks. It behaves exactly as before. CC:
(none) =>
tarazed25 Addendum to comment 4. One way to generate an m3u file which mopidy might accept as a playlist would be to create one by playing tracks and adding them to a new playlist. Validating. Keywords:
(none) =>
validated_update
Dave Hodgins
2023-06-27 22:44:51 CEST
CC:
(none) =>
davidwhodgins An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0211.html Status:
NEW =>
RESOLVED |