Path to this page:
Subject: CVS commit: pkgsrc/www/py-tornado
From: Adam Ciarcinski
Date: 2024-11-22 09:25:28
Message id: 20241122082528.7AC7BFC7D@cvs.NetBSD.org
Log Message:
py-tornado: updated to 6.4.2
What's new in Tornado 6.4.2
Security Improvements
- Parsing of the cookie header is now much more efficient. The older algorithm \
sometimes had
quadratic performance which allowed for a denial-of-service attack in which \
the server would spend
excessive CPU time parsing cookies and block the event loop. This change fixes \
CVE-2024-7592.
Files: