Oval Definition:oval:org.opensuse.security:def:5535
Revision Date:2020-12-02Version:1
Title:Security update for python-waitress (Moderate)
Description:

This update for python-waitress to 1.4.3 fixes the following security issues:

- CVE-2019-16785: HTTP request smuggling through LF vs CRLF handling (bsc#1161088). - CVE-2019-16786: HTTP request smuggling through invalid Transfer-Encoding (bsc#1161089). - CVE-2019-16789: HTTP request smuggling through invalid whitespace characters (bsc#1160790). - CVE-2019-16792: HTTP request smuggling by sending the Content-Length header twice (bsc#1161670).
Family:unixClass:patch
Status:Reference(s):1160790
1161088
1161089
1161670
1162629
1162632
1165280
1165289
CVE-2009-4492
CVE-2010-0541
CVE-2010-0624
CVE-2011-0904
CVE-2011-0905
CVE-2011-1004
CVE-2011-1005
CVE-2011-1164
CVE-2011-2483
CVE-2011-4815
CVE-2012-4559
CVE-2012-4560
CVE-2012-4561
CVE-2013-0176
CVE-2013-1990
CVE-2013-1999
CVE-2013-3571
CVE-2013-4242
CVE-2013-6370
CVE-2013-6371
CVE-2014-0017
CVE-2014-0019
CVE-2014-1932
CVE-2014-3591
CVE-2014-8132
CVE-2014-8484
CVE-2014-8485
CVE-2014-8501
CVE-2014-8502
CVE-2014-8503
CVE-2014-8504
CVE-2014-8737
CVE-2014-8738
CVE-2015-0837
CVE-2015-1191
CVE-2015-3146
CVE-2015-4000
CVE-2015-7511
CVE-2015-8872
CVE-2016-0739
CVE-2016-4804
CVE-2016-6313
CVE-2019-16785
CVE-2019-16786
CVE-2019-16789
CVE-2019-16792
CVE-2020-7059
CVE-2020-7060
CVE-2020-7062
CVE-2020-7063
SUSE-SU-2020:0622-1
SUSE-SU-2020:3269-1
Platform(s):openSUSE 13.1
SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise for SAP 12
SUSE Linux Enterprise for SAP 12 SP1
SUSE Linux Enterprise High Performance Computing 12 SP5
SUSE Linux Enterprise Module for Containers 12
SUSE Linux Enterprise Module for High Performance Computing 12
SUSE Linux Enterprise Module for Legacy Software 12
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Module for Toolchain 12
SUSE Linux Enterprise Module for Web Scripting 12
SUSE Linux Enterprise Real Time Extension 11 SP4
SUSE Linux Enterprise Server 11 SP1-LTSS
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2-LTSS
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for VMWare 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Linux Enterprise Software Development Kit 11 SP4
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Software Development Kit 12 SP1
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP4
SUSE Linux Enterprise Workstation Extension 12
SUSE Linux Enterprise Workstation Extension 12 SP1
SUSE Linux Enterprise Workstation Extension 12 SP2
SUSE OpenStack Cloud 5
Product(s):
Definition Synopsis
  • SUSE Cloud Compute Node for SUSE Linux Enterprise 12 5 is installed
  • AND python-requests-2.8.1-6.9.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • flash-player-11.2.202.508-0.14.1 is installed
  • OR flash-player-gnome-11.2.202.508-0.14.1 is installed
  • OR flash-player-kde4-11.2.202.508-0.14.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND python-imaging-1.1.7-21 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP2 is installed
  • AND binutils-2.26.1-9.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • bzip2-1.0.6-29 is installed
  • OR libbz2-1-1.0.6-29 is installed
  • OR libbz2-1-32bit-1.0.6-29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • colord-1.3.3-12 is installed
  • OR colord-gtk-lang-0.1.26-6 is installed
  • OR colord-lang-1.3.3-12 is installed
  • OR libcolord-gtk1-0.1.26-6 is installed
  • OR libcolord2-1.3.3-12 is installed
  • OR libcolord2-32bit-1.3.3-12 is installed
  • OR libcolorhug2-1.3.3-12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise for SAP 12 is installed
  • AND Package Information
  • kgraft-patch-3_12_60-52_49-default-2-2.2 is installed
  • OR kgraft-patch-3_12_60-52_49-xen-2-2.2 is installed
  • OR kgraft-patch-SLE12_Update_14-2-2.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise for SAP 12 SP1 is installed
  • AND Package Information
  • compat-openssl098-0.9.8j-102.1 is installed
  • OR libopenssl0_9_8-0.9.8j-102.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
  • AND Package Information
  • cpio-2.11-36.3 is installed
  • OR cpio-lang-2.11-36.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Containers 12 is installed
  • AND Package Information
  • containerd-0.2.5+gitr569_2a5e70c-15 is installed
  • OR docker-1.12.6-87 is installed
  • OR runc-0.1.1+gitr2819_50a19c6-15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for High Performance Computing 12 is installed
  • AND Package Information
  • libpmi0-17.02.9-6.10 is installed
  • OR libslurm29-16.05.8.1-6 is installed
  • OR libslurm31-17.02.9-6.10 is installed
  • OR pdsh-2.33-7.5 is installed
  • OR perl-slurm-17.02.9-6.10 is installed
  • OR slurm-17.02.9-6.10 is installed
  • OR slurm-auth-none-17.02.9-6.10 is installed
  • OR slurm-devel-17.02.9-6.10 is installed
  • OR slurm-doc-17.02.9-6.10 is installed
  • OR slurm-lua-17.02.9-6.10 is installed
  • OR slurm-munge-17.02.9-6.10 is installed
  • OR slurm-pam_slurm-17.02.9-6.10 is installed
  • OR slurm-plugins-17.02.9-6.10 is installed
  • OR slurm-sched-wiki-17.02.9-6.10 is installed
  • OR slurm-slurmdb-direct-17.02.9-6.10 is installed
  • OR slurm-slurmdbd-17.02.9-6.10 is installed
  • OR slurm-sql-17.02.9-6.10 is installed
  • OR slurm-torque-17.02.9-6.10 is installed
  • OR slurmlibs-16.05.8.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Legacy Software 12 is installed
  • AND Package Information
  • compat-openssl098-0.9.8j-87 is installed
  • OR libopenssl0_9_8-0.9.8j-87 is installed
  • OR libopenssl0_9_8-32bit-0.9.8j-87 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Public Cloud 12 is installed
  • AND python-pycrypto-2.6.1-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Toolchain 12 is installed
  • AND Package Information
  • cpp5-5.3.1+r233831-9.1 is installed
  • OR gcc5-5.3.1+r233831-9.1 is installed
  • OR gcc5-32bit-5.3.1+r233831-9.1 is installed
  • OR gcc5-ada-5.3.1+r233831-9.1 is installed
  • OR gcc5-ada-32bit-5.3.1+r233831-9.1 is installed
  • OR gcc5-c++-5.3.1+r233831-9.1 is installed
  • OR gcc5-c++-32bit-5.3.1+r233831-9.1 is installed
  • OR gcc5-fortran-5.3.1+r233831-9.1 is installed
  • OR gcc5-fortran-32bit-5.3.1+r233831-9.1 is installed
  • OR gcc5-info-5.3.1+r233831-9.1 is installed
  • OR gcc5-locale-5.3.1+r233831-9.1 is installed
  • OR libada5-5.3.1+r233831-9.1 is installed
  • OR libada5-32bit-5.3.1+r233831-9.1 is installed
  • OR libffi-devel-gcc5-5.3.1+r233831-9.1 is installed
  • OR libffi-devel-gcc5-32bit-5.3.1+r233831-9.1 is installed
  • OR libffi-gcc5-5.3.1+r233831-9.1 is installed
  • OR libstdc++6-devel-gcc5-5.3.1+r233831-9.1 is installed
  • OR libstdc++6-devel-gcc5-32bit-5.3.1+r233831-9.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Web Scripting 12 is installed
  • AND Package Information
  • apache2-mod_php5-5.5.14-30.1 is installed
  • OR php5-5.5.14-30.1 is installed
  • OR php5-bcmath-5.5.14-30.1 is installed
  • OR php5-bz2-5.5.14-30.1 is installed
  • OR php5-calendar-5.5.14-30.1 is installed
  • OR php5-ctype-5.5.14-30.1 is installed
  • OR php5-curl-5.5.14-30.1 is installed
  • OR php5-dba-5.5.14-30.1 is installed
  • OR php5-dom-5.5.14-30.1 is installed
  • OR php5-enchant-5.5.14-30.1 is installed
  • OR php5-exif-5.5.14-30.1 is installed
  • OR php5-fastcgi-5.5.14-30.1 is installed
  • OR php5-fileinfo-5.5.14-30.1 is installed
  • OR php5-fpm-5.5.14-30.1 is installed
  • OR php5-ftp-5.5.14-30.1 is installed
  • OR php5-gd-5.5.14-30.1 is installed
  • OR php5-gettext-5.5.14-30.1 is installed
  • OR php5-gmp-5.5.14-30.1 is installed
  • OR php5-iconv-5.5.14-30.1 is installed
  • OR php5-intl-5.5.14-30.1 is installed
  • OR php5-json-5.5.14-30.1 is installed
  • OR php5-ldap-5.5.14-30.1 is installed
  • OR php5-mbstring-5.5.14-30.1 is installed
  • OR php5-mcrypt-5.5.14-30.1 is installed
  • OR php5-mysql-5.5.14-30.1 is installed
  • OR php5-odbc-5.5.14-30.1 is installed
  • OR php5-openssl-5.5.14-30.1 is installed
  • OR php5-pcntl-5.5.14-30.1 is installed
  • OR php5-pdo-5.5.14-30.1 is installed
  • OR php5-pear-5.5.14-30.1 is installed
  • OR php5-pgsql-5.5.14-30.1 is installed
  • OR php5-pspell-5.5.14-30.1 is installed
  • OR php5-shmop-5.5.14-30.1 is installed
  • OR php5-snmp-5.5.14-30.1 is installed
  • OR php5-soap-5.5.14-30.1 is installed
  • OR php5-sockets-5.5.14-30.1 is installed
  • OR php5-sqlite-5.5.14-30.1 is installed
  • OR php5-suhosin-5.5.14-30.1 is installed
  • OR php5-sysvmsg-5.5.14-30.1 is installed
  • OR php5-sysvsem-5.5.14-30.1 is installed
  • OR php5-sysvshm-5.5.14-30.1 is installed
  • OR php5-tokenizer-5.5.14-30.1 is installed
  • OR php5-wddx-5.5.14-30.1 is installed
  • OR php5-xmlreader-5.5.14-30.1 is installed
  • OR php5-xmlrpc-5.5.14-30.1 is installed
  • OR php5-xmlwriter-5.5.14-30.1 is installed
  • OR php5-xsl-5.5.14-30.1 is installed
  • OR php5-zip-5.5.14-30.1 is installed
  • OR php5-zlib-5.5.14-30.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Real Time Extension 11 SP4 is installed
  • AND Package Information
  • kernel-rt-3.0.101.rt130-54.1 is installed
  • OR kernel-rt-base-3.0.101.rt130-54.1 is installed
  • OR kernel-rt-devel-3.0.101.rt130-54.1 is installed
  • OR kernel-rt_trace-3.0.101.rt130-54.1 is installed
  • OR kernel-rt_trace-base-3.0.101.rt130-54.1 is installed
  • OR kernel-rt_trace-devel-3.0.101.rt130-54.1 is installed
  • OR kernel-source-rt-3.0.101.rt130-54.1 is installed
  • OR kernel-syms-rt-3.0.101.rt130-54.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP1-LTSS is installed
  • AND Package Information
  • libpython2_6-1_0-2.6.9-0.31.1 is installed
  • OR libpython2_6-1_0-32bit-2.6.9-0.31.1 is installed
  • OR python-2.6.9-0.31.1 is installed
  • OR python-32bit-2.6.9-0.31.1 is installed
  • OR python-base-2.6.9-0.31.1 is installed
  • OR python-base-32bit-2.6.9-0.31.1 is installed
  • OR python-curses-2.6.9-0.31.1 is installed
  • OR python-demo-2.6.9-0.31.1 is installed
  • OR python-devel-2.6.9-0.31.1 is installed
  • OR python-doc-2.6-8.31.1 is installed
  • OR python-doc-pdf-2.6-8.31.1 is installed
  • OR python-gdbm-2.6.9-0.31.1 is installed
  • OR python-idle-2.6.9-0.31.1 is installed
  • OR python-tk-2.6.9-0.31.1 is installed
  • OR python-xml-2.6.9-0.31.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP2 is installed
  • AND fastjar-0.95-1.24.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server for VMWare 11 SP2 is installed
  • AND fastjar-0.95-1.24.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP2 is installed
  • AND Package Information
  • apache2-2.2.12-1.28.1 is installed
  • OR apache2-doc-2.2.12-1.28.1 is installed
  • OR apache2-example-pages-2.2.12-1.28.1 is installed
  • OR apache2-prefork-2.2.12-1.28.1 is installed
  • OR apache2-utils-2.2.12-1.28.1 is installed
  • OR apache2-worker-2.2.12-1.28.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND Package Information
  • bzip2-1.0.5-34.253.1 is installed
  • OR bzip2-doc-1.0.5-34.253.1 is installed
  • OR libbz2-1-1.0.5-34.253.1 is installed
  • OR libbz2-1-32bit-1.0.5-34.253.1 is installed
  • OR libbz2-1-x86-1.0.5-34.253.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP4 is installed
  • AND Package Information
  • PolicyKit-0.9-14.43.1 is installed
  • OR PolicyKit-32bit-0.9-14.43.1 is installed
  • OR PolicyKit-doc-0.9-14.43.1 is installed
  • OR PolicyKit-x86-0.9-14.43.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 is installed
  • AND Package Information
  • aaa_base-13.2+git20140911.61c1681-1 is installed
  • OR aaa_base-extras-13.2+git20140911.61c1681-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND ant-1.9.4-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • bzip2-1.0.6-29 is installed
  • OR bzip2-doc-1.0.6-29 is installed
  • OR libbz2-1-1.0.6-29 is installed
  • OR libbz2-1-32bit-1.0.6-29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND sane-backends-1.0.24-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND apache2-mod_jk-1.2.40-5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP1 is installed
  • AND Package Information
  • emacs-24.3-25.3 is installed
  • OR emacs-el-24.3-25.3 is installed
  • OR emacs-info-24.3-25.3 is installed
  • OR emacs-nox-24.3-25.3 is installed
  • OR emacs-x11-24.3-25.3 is installed
  • OR etags-24.3-25.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 15 is installed
  • AND Package Information
  • python-waitress-1.4.3-3.3 is installed
  • OR python3-waitress-1.4.3-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 11 SP2 is installed
  • AND Package Information
  • apache2-2.2.12-1.40.1 is installed
  • OR apache2-devel-2.2.12-1.40.1 is installed
  • OR apache2-doc-2.2.12-1.40.1 is installed
  • OR apache2-example-pages-2.2.12-1.40.1 is installed
  • OR apache2-prefork-2.2.12-1.40.1 is installed
  • OR apache2-utils-2.2.12-1.40.1 is installed
  • OR apache2-worker-2.2.12-1.40.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
  • AND libexpat-devel-2.0.1-88.34.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 12 is installed
  • AND Package Information
  • avahi-compat-howl-devel-0.6.31-20 is installed
  • OR avahi-compat-mDNSResponder-devel-0.6.31-20 is installed
  • OR libavahi-devel-0.6.31-20 is installed
  • OR libhowl0-0.6.31-20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 12 SP1 is installed
  • AND Package Information
  • binutils-devel-2.25.0-13 is installed
  • OR binutils-gold-2.25.0-13 is installed
  • OR cross-ppc-binutils-2.25.0-13 is installed
  • OR cross-spu-binutils-2.25.0-13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 12 SP3 is installed
  • AND net-snmp-devel-5.7.3-4 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
  • AND Package Information
  • ImageMagick-6.8.8.1-71.85 is installed
  • OR ImageMagick-devel-6.8.8.1-71.85 is installed
  • OR libMagick++-6_Q16-3-6.8.8.1-71.85 is installed
  • OR libMagick++-devel-6.8.8.1-71.85 is installed
  • OR perl-PerlMagick-6.8.8.1-71.85 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 12 is installed
  • AND bogofilter-1.2.4-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 12 SP1 is installed
  • AND Package Information
  • finch-2.10.9-8 is installed
  • OR libpurple-2.10.9-8 is installed
  • OR libpurple-lang-2.10.9-8 is installed
  • OR libpurple-meanwhile-2.10.9-8 is installed
  • OR libpurple-tcl-2.10.9-8 is installed
  • OR pidgin-2.10.9-8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 12 SP2 is installed
  • AND argyllcms-1.6.3-3 is installed
  • BACK