Security review:
* One CVE: CVE-2012-2374. Issue was fixed prompted and with a one line patch
* Python library
* Lintian clean, no initscripts/upstart jobs, no dbus services, not 
setuid/fscaps/sudo/pkexec, no cron jobs. Has a testsuite, but not enabled.
* Uses the system ca-certificates file. Defaults to certificate verification.
* Minor nit: demos have predictable filenames in /tmp

Conditional ACK provided the testsuite is enabled.

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2012-2374

** Changed in: python-tornado (Ubuntu)
       Status: Incomplete => In Progress

** Changed in: python-tornado (Ubuntu)
     Assignee: Jamie Strandboge (jdstrand) => Chuck Short (zulcss)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1047432

Title:
  [MIR] python-tornado

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/python-tornado/+bug/1047432/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to