Gentoo Security Advisory GLSA 200605-16 (cherrypy)

Summary
The remote host is missing updates announced in advisory GLSA 200605-16.
Solution
All CherryPy users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=dev-python/cherrypy-2.1.1' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200605-16 http://bugs.gentoo.org/show_bug.cgi?id=134273
Insight
CherryPy is vulnerable to a directory traversal that could allow attackers to read arbitrary files.