Debian Security Advisory

DSA-3743-1 python-bottle -- security update

Date Reported:
20 Dec 2016
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 848392.
In Mitre's CVE dictionary: CVE-2016-9964.
More information:

It was discovered that bottle, a WSGI-framework for the Python programming language, did not properly filter "\r\n" sequences when handling redirections. This allowed an attacker to perform CRLF attacks such as HTTP header injection.

For the stable distribution (jessie), this problem has been fixed in version 0.12.7-1+deb8u1.

For the testing (stretch) and unstable (sid) distributions, this problem has been fixed in version 0.12.11-1.

We recommend that you upgrade your python-bottle packages.