USN-6159-1: Tornado vulnerability
13 June 2023
Tornado could be made to redirect users to arbitrary web site if it opened a specially crafted URL.
Releases
Packages
- python-tornado - scalable, non-blocking web server and tools - documentation
Details
It was discovered that Tornado incorrectly handled certain redirect.
An remote attacker could possibly use this issue to redirect a user to an
arbitrary web site and conduct a phishing attack by having user access a
specially crafted URL.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
Ubuntu 16.04
-
python-tornado
-
4.2.1-1ubuntu3.1+esm1
Available with Ubuntu Pro
-
python3-tornado
-
4.2.1-1ubuntu3.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.