Your message dated Fri, 09 Feb 2024 22:55:19 +0000
with message-id <[email protected]>
and subject line Bug#1054553: fixed in python-werkzeug 3.0.1-2
has caused the Debian Bug report #1054553,
regarding python-werkzeug: CVE-2023-46136
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1054553: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1054553
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-werkzeug
Version: 2.2.2-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for python-werkzeug.
CVE-2023-46136[0]:
| Werkzeug is a comprehensive WSGI web application library. If an
| upload of a file that starts with CR or LF and then is followed by
| megabytes of data without these characters: all of these bytes are
| appended chunk by chunk into internal bytearray and lookup for
| boundary is performed on growing buffer. This allows an attacker to
| cause a denial of service by sending crafted multipart data to an
| endpoint that will parse it. The amount of CPU time required can
| block worker processes from handling legitimate requests. This
| vulnerability has been patched in version 3.0.1.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2023-46136
https://www.cve.org/CVERecord?id=CVE-2023-46136
[1] https://github.com/pallets/werkzeug/security/advisories/GHSA-hrfv-mqp8-q5rw
[2]
https://github.com/pallets/werkzeug/commit/b1916c0c083e0be1c9d887ee2f3d696922bfc5c1
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: python-werkzeug
Source-Version: 3.0.1-2
Done: Carsten Schoenert <[email protected]>
We believe that the bug you reported is fixed in the latest version of
python-werkzeug, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Carsten Schoenert <[email protected]> (supplier of updated
python-werkzeug package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 09 Feb 2024 19:32:22 +0100
Source: python-werkzeug
Architecture: source
Version: 3.0.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Closes: 1054553 1058244
Changes:
python-werkzeug (3.0.1-2) unstable; urgency=medium
.
* Team upload
.
[ Julian Gilbey ]
* Add python3-markupsafe Build-Depends
.
[ Carsten Schoenert ]
* Upload to unstable
Fixes CVE-2023-46136
(Closes: #1054553, #1058244)
Checksums-Sha1:
63845edbd392b71fa8453806d64fbed54216638d 2872 python-werkzeug_3.0.1-2.dsc
83cbbbe74dd38f22957a837ec1e77831b0b263b1 17916
python-werkzeug_3.0.1-2.debian.tar.xz
dc88bbd1bc60c81a5d6092b5d2e788dca2c574c7 9083
python-werkzeug_3.0.1-2_amd64.buildinfo
Checksums-Sha256:
e9e5bb0bc94dd1640b3b00e9a6e3e71f620df500b9d7bd5ebd65a43e71bacede 2872
python-werkzeug_3.0.1-2.dsc
c7ed75b2960e456db7d354859c295c2cb95fc4973b43df1ef78fe236d163d585 17916
python-werkzeug_3.0.1-2.debian.tar.xz
9f0b9e22e3f216c6d51bd9138316f82b76169abe97cfd4df5f1f4bb046e92a85 9083
python-werkzeug_3.0.1-2_amd64.buildinfo
Files:
2279d51818dc41ae1adbb1185c1736a2 2872 python optional
python-werkzeug_3.0.1-2.dsc
ad6983857d0800cbdf1cad97212c573c 17916 python optional
python-werkzeug_3.0.1-2.debian.tar.xz
25506fdf419b541e873c42501b05ab40 9083 python optional
python-werkzeug_3.0.1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmXGdAUYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wZZoP/1s73m9cbTayq19lQs6ExQR5
tEMc0ZDf7y9nTEXrD/KTdfBhQ4w3p7NnjFCe3ibS0C1p/nzlktW71P8gj3Jghx3d
jNg8plz8xoMwCCIKuOH6ijeykkQPssp8zmxvJLR6El+bY5kKOhPjkt4+o3sbnXkL
fwIz7Jt1TiIJgqWytHDzbVTPIt4KtJ1OXfl/gs2B40chkKbNbZDD8ql+y2fCMKMV
h/bbZfNUPBNqLk9ABurtuIBcvDxtxPj9O+86H/B961ZJXeWMBEJiC48oWYB1Y0lh
1sOck/kCvScISOCLjOvVf6Iev9TV2SND1Y8+pZxH5MCHIBOWRQQ0d1kC9Ob7mXyW
KIVtNhrU3Brus5DksEFbijNutRVcGRjTLwXTBMvQ2Clw9+N3bTWd8N27+tuCdEUm
AhRiXVLvhwQ58YAxyfbgcB0QRioDeKrcQmwTGOfG91Q5Kjmw5yeBkTIkluivLCfQ
HtipSs2LtU+Ow+DBteTMmawEeoArPNW3PGEx19W71twAmp5pvlvXVrWxlfeP67+e
Dl7a501bTrRfErNxQS9W96urP8DN+2whjO5B49BrVZuIw1gi0DKpnxz6gelfaqqP
yQk6DBsnK6AD7nYimpUgi+jLvVI9w0BlgUi60tLICdfRdY+PcPbY1kYbDdyoW8+b
cQUyZRk+bW9G4MQIrxaz
=UBtJ
-----END PGP SIGNATURE-----
--- End Message ---