-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 15 May 2016 19:04:18 +0200 Source: python-tornado Binary: python-tornado python3-tornado Architecture: source all Version: 2.3-2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: python-tornado - scalable, non-blocking web server and tools python3-tornado - scalable, non-blocking web server and tools - Python 3 package Changes: python-tornado (2.3-2+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Add CVE-2014-9720.patch. The XSRF token is now encoded with a random mask on each request. This makes it safe to include in compressed pages without being vulnerable to the BREACH attack. This applies to most applications that use both the xsrf_cookies and gzip options (or have gzip applied by a proxy). Checksums-Sha1: 4956a21baaa72a6153c4b4508a535b16c42d8815 2285 python-tornado_2.3-2+deb7u1.dsc 0abec6acc2ba880caadfda690cdeb73f445bc072 338950 python-tornado_2.3.orig.tar.gz 52a8dab5c7e576dfbf6bdd7efb6d4f34fba8acc0 16873 python-tornado_2.3-2+deb7u1.debian.tar.gz 96e3404367e18653f43b77823847eacce55a27ae 253584 python-tornado_2.3-2+deb7u1_all.deb 7fd7a6f0bc3331a8a226675407d1002bd87bb8f8 181990 python3-tornado_2.3-2+deb7u1_all.deb Checksums-Sha256: 5dfcedecb8cbb5c1bdbd55ac888eaa0d07eea29509d30cc34b9026c4a5d37541 2285 python-tornado_2.3-2+deb7u1.dsc 627ef58b7134781c814ac81d83cd435d4b9ebf3b5ba94c2102a1259740c4415c 338950 python-tornado_2.3.orig.tar.gz 84b07560bcd60da86b309994ac0874a89b878c90adc70c90b9415f3b11894d5e 16873 python-tornado_2.3-2+deb7u1.debian.tar.gz 7032ec725bee29fd7c826610cf068da0b56fa4130c1cf724d0532b8de8114bad 253584 python-tornado_2.3-2+deb7u1_all.deb b9006daeb2ae85e102f719988fe3f3ae50f2b8f2073ffaaf7b4089c7a6f9e37d 181990 python3-tornado_2.3-2+deb7u1_all.deb Files: c8e3cb7d7b57a4b787d09525c8ad14e6 2285 web optional python-tornado_2.3-2+deb7u1.dsc 810c3ecd425924fbf0aa1fa040f93ad1 338950 web optional python-tornado_2.3.orig.tar.gz fceec4d173029b12ce69c1cd71495d1a 16873 web optional python-tornado_2.3-2+deb7u1.debian.tar.gz 36082391e93e7560b8ae15c53efce037 253584 web optional python-tornado_2.3-2+deb7u1_all.deb f6f4413807132a9984a136ee3cb054d5 181990 web optional python3-tornado_2.3-2+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJXOMn+XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE OUFEMTRCOTUxM0I1MUU0AAoJENmtFLlRO1HkBMQP/3vbGIhIovxCbC6CpXPTgQCz aiB/UjPKzwiTPpcx/acmM8BLIcl7tkRWPoGKz7LoVSS8RZ1iVI9dZfzwG4+zAuV7 2ihMmwbtHNOarSBUZMBiP6DNVCcUKJkXoHNl9f2Tsr5DDA1vS/XoHKvZ6iV0UZhe NjyItqykBx88UmNEBretj+BId2zQeiIfO5zUOtIEJtT8k6UM1iykKeVO+2zg1B1s OzkgHR5kFXSwf7t25LzHw3Q9KZ74cT6vpFEyczqnu+y4vcIUC10c6yaeo+MiibG/ OI3Q/AUyt4oEKX4aI5uX+ZOH/KiAio6AnqgBoaiqQBGhTmnYOuORE3MfoNnjMthy qLI+4Kgq1Fo48Zbk+wDO8bsa7bTMV7NcT+eKRzQXy95tckX/9FDTNQcuft4nSuvP ZJsr9Kw219UJwFx+/LS3HizhGQ6ZLUlj5pMfIRXl47Z9oXuK63rJgZYadX13UR5S 6Wv7gnJ4iFUJSM4ADW7kyhZLRgTurUA7OKqTTqGl/zIPy+7YsJyM0hBdeuK69ZdV SQMJEPADthTF087FkPmEwD0XvUXlVWtWuKPgzofas0KP8G2xlTdj+kWaC6jIgt+s v5W2KO1rARL1VxajycC5xMnnXqCMjE1oondHT6jmqiAJkzS2fFgL8jsTG7DaBQcq ebJseu2ED47pVO/ntG9y =WZOr -----END PGP SIGNATURE-----