Bug#793770: Cookie parsing bug may lead to 'HttpOnly' cookie bypass (CVE-2015-2156)

2017-01-09 Thread Emmanuel Bourg
Le 9/01/2017 à 23:37, Moritz Muehlenhoff a écrit : > This is unfixed with a patch for nearly 1.5 years, can we please get this > fixed for the stretch release. Hi Moritz, Thank you for the reminder. The fix was backported in the version 3.9.7. I'll update the package to the latest 3.9.x

Bug#793770: Cookie parsing bug may lead to 'HttpOnly' cookie bypass (CVE-2015-2156)

2017-01-09 Thread Moritz Muehlenhoff
severity 793770 grave thanks On Mon, Jul 27, 2015 at 11:51:53AM +0200, Luca Bruno wrote: > Source: netty-3.9 > Version: 3.9.0.Final-1 > Severity: important > Tags: security upstream patch > > LinkedIn Security Team discovered a "Cookie" header parsing bug in Netty > that could lead to universal