Gentoo: GLSA-200605-16: CherryPy: Directory traversal vulnerability
Summary
Gentoo Linux Security Advisory GLSA 200605-16
https://security.gentoo.org/
Severity: Low
Title: CherryPy: Directory traversal vulnerability
Date: May 30, 2006
Bugs: #134273
ID: 200605-16
Synopsis
=======
CherryPy is vulnerable to a directory traversal that could allow
attackers to read arbitrary files.
Background
=========
CherryPy is a Python-based, object-oriented web development framework.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-python/cherrypy < 2.1.1 >= 2.1.1
==========
Ivo van der Wijk discovered that the "staticfilter" component of
CherryPy fails to sanitize input correctly.
Impact
=====
An attacker could exploit this flaw to obtai...
Resolution
References
Availability
Concerns
Background