ELA-851-1 uwsgi security update

Inconsistent Interpretation of HTTP Requests (HTTP Response Smuggling) vulnerability

2023-05-20
Packageuwsgi
Version2.0.14+20161117-3+deb9u6 (stretch)
Related CVEs CVE-2023-27522


A HTTP Response Smuggling vulnerability was fixed mod_proxy_uwsgi apache module included in uwsgi package. Special characters in the origin response header can truncate/split the response forwarded to the client.



For Debian 9 stretch, these problems have been fixed in version 2.0.14+20161117-3+deb9u6.

We recommend that you upgrade your uwsgi packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.