It was discovered that bottle, a WSGI-framework for the Python programming language, did not properly filter "\r\n" sequences when handling redirections. This allowed an attacker to perform CRLF attacks such as HTTP header injection. For the stable distribution (jessie), this problem has been fixed in version 0.12.7-1+deb8u1. For the testing (stretch) and unstable (sid) distributions, this problem has been fixed in version 0.12.11-1. We recommend that you upgrade your python-bottle packages.
It was discovered that bottle, a WSGI-framework for the Python programming language, did not properly filter "\r\n" sequences when handling redirections. This allowed an attacker to perform CRLF attacks such as HTTP header injection.
For the stable distribution (jessie), this problem has been fixed in version 0.12.7-1+deb8u1.
For the testing (stretch) and unstable (sid) distributions, this problem has been fixed in version 0.12.11-1.
We recommend that you upgrade your python-bottle packages.