Headline
Ubuntu Security Notice USN-6159-1
Ubuntu Security Notice 6159-1 - It was discovered that Tornado incorrectly handled certain redirect. An remote attacker could possibly use this issue to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
=========================================================================Ubuntu Security Notice USN-6159-1June 13, 2023python-tornado vulnerability=========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.04- Ubuntu 16.04 LTS (Available with Ubuntu Pro)Summary:Tornado could be made to redirect users to arbitrary web site if it opened aspecially crafted URL.Software Description:- python-tornado: scalable, non-blocking web server and tools - documentationDetails:It was discovered that Tornado incorrectly handled certain redirect.An remote attacker could possibly use this issue to redirect a user to anarbitrary web site and conduct a phishing attack by having user access aspecially crafted URL.Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.04: python3-tornado 6.2.0-3ubuntu0.1Ubuntu 16.04 LTS (Available with Ubuntu Pro): python-tornado 4.2.1-1ubuntu3.1+esm1 python3-tornado 4.2.1-1ubuntu3.1+esm1In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-6159-1 CVE-2023-28370Package Information: https://launchpad.net/ubuntu/+source/python-tornado/6.2.0-3ubuntu0.1
Related news
GHSA-hj3f-6gcp-jg8j: Open redirect in Tornado
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
CVE-2023-28370: Tornado vulnerable to open redirect
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.