Debian Package Tracker
Register | Log in
Subscribe

python-tornado

Choose email to subscribe with

general
  • source: python-tornado (main)
  • version: 6.4.2-2
  • maintainer: Debian Python Team (DMD)
  • uploaders: Julien Puydt [DMD] – Julian Taylor [DMD] – Yaroslav Halchenko [DMD] – Carl Chenet [DMD]
  • arch: all any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.1.1-4
  • oldstable: 6.1.0-1
  • old-sec: 6.1.0-1+deb11u1
  • stable: 6.2.0-3+deb12u1
  • testing: 6.4.2-1
  • unstable: 6.4.2-2
versioned links
  • 5.1.1-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.1.0-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.2.0-3+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.4.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-tornado-doc
  • python3-tornado
action needed
A new upstream version is available: 6.5.0 high
A new upstream version 6.5.0 is available, you should consider packaging it.
Created: 2025-05-04 Last update: 2025-05-20 21:32
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Created: 2025-05-16 Last update: 2025-05-19 01:29
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Created: 2025-05-16 Last update: 2025-05-19 01:29
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Created: 2025-05-16 Last update: 2025-05-19 01:29
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2025-05-20 Last update: 2025-05-21 02:01
lintian reports 6 warnings normal
Lintian reports 6 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2024-01-22 Last update: 2024-11-29 22:03
debian/patches: 2 patches to forward upstream low

Among the 7 debian patches available in version 6.4.2-2 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2024-09-25 Last update: 2025-05-19 10:22
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-05-19 02:01
testing migrations
  • excuses:
    • Migration status for python-tornado (6.4.2-1 to 6.4.2-2): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Updating python-tornado would introduce bugs in testing: #1106130
    • ∙ ∙ missing build on riscv64
    • ∙ ∙ blocked by freeze: is a key package (Follow the freeze policy when applying for an unblock)
    • ∙ ∙ arch:riscv64 not built yet, autopkgtest delayed there
    • ∙ ∙ autopkgtest for python-tornado/6.4.2-2: amd64: Pass, arm64: Pass, armel: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Pass
    • ∙ ∙ Too young, only 2 of 20 days old
    • Additional info:
    • ∙ ∙ Updating python-tornado will fix bugs in testing: #1105886
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/p/python-tornado.html
    • ∙ ∙ Reproducible on amd64 - info ♻
    • ∙ ∙ Reproducible on arm64 - info ♻
    • ∙ ∙ Waiting for reproducibility test results on armhf - info ♻
    • ∙ ∙ Reproducible on i386 - info ♻
    • Not considered
news
[rss feed]
  • [2025-05-18] Accepted python-tornado 6.4.2-2 (source) into unstable (Colin Watson)
  • [2025-01-03] Accepted python-tornado 6.2.0-3+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Daniel Leidert)
  • [2025-01-01] Accepted python-tornado 6.1.0-1+deb11u1 (source) into oldstable-security (Daniel Leidert)
  • [2024-12-04] python-tornado 6.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-29] Accepted python-tornado 6.4.2-1 (source) into unstable (Colin Watson)
  • [2024-09-30] python-tornado 6.4.1-3 MIGRATED to testing (Debian testing watch)
  • [2024-09-25] Accepted python-tornado 6.4.1-3 (source) into unstable (Alexandre Detiste)
  • [2024-08-25] python-tornado 6.4.1-2 MIGRATED to testing (Debian testing watch)
  • [2024-08-19] Accepted python-tornado 6.4.1-2 (source) into unstable (Colin Watson)
  • [2024-06-20] python-tornado 6.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-20] python-tornado 6.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-13] Accepted python-tornado 6.4.1-1 (source) into unstable (Julien Puydt)
  • [2024-06-03] python-tornado 6.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-05-29] Accepted python-tornado 6.4.0-2 (source) into unstable (Timo Röhling)
  • [2024-01-24] python-tornado 6.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-21] Accepted python-tornado 6.4.0-1 (source) into unstable (Stefano Rivera)
  • [2023-06-28] python-tornado 6.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-26] Accepted python-tornado 6.3.2-1 (source) into unstable (Julien Puydt)
  • [2022-11-22] python-tornado 6.2.0-3 MIGRATED to testing (Debian testing watch)
  • [2022-11-20] Accepted python-tornado 6.2.0-3 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2022-10-19] python-tornado 6.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-10-17] Accepted python-tornado 6.2.0-2 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2022-08-20] python-tornado 6.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-10] Accepted python-tornado 6.2.0-1 (source) into unstable (Julien Puydt)
  • [2021-12-05] python-tornado 6.1.0-3 MIGRATED to testing (Debian testing watch)
  • [2021-12-03] Accepted python-tornado 6.1.0-3 (source) into unstable (Julien Puydt)
  • [2021-11-23] python-tornado 6.1.0-2 MIGRATED to testing (Debian testing watch)
  • [2021-11-21] Accepted python-tornado 6.1.0-2 (source) into unstable (Stefano Rivera)
  • [2020-11-18] python-tornado 6.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-14] Accepted python-tornado 6.1.0-1 (source) into unstable (Gordon Ball)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 6)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 100)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 6.4.2-2
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing