Bug#746322: CVE request: Python Bottle JSON content-type not restrictive enough

2014-05-01 Thread cve-assign
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746322 and https://github.com/defnull/bottle/issues/616 report an issue where Bottle treated text/plain;application/json as JSON, allowing security mechanisms to be bypassed. Use CVE-2014-3137.

Bug#746322: CVE request: Python Bottle JSON content-type not restrictive enough

2014-04-30 Thread Murray McAllister
Hi, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=746322 and https://github.com/defnull/bottle/issues/616 report an issue where Bottle treated text/plain;application/json as JSON, allowing security mechanisms to be bypassed. From the upstream report, For example Chrome will not allow