Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian LTS Version 9: DLA-2927-1 Critical: Twisted HTTP Request Issues

debian lts
Calendar Grey February 19, 2022
Dist Debian Esm H88
Enhance Twisted to resolve HTTP request fragmentation vulnerabilities that compromise sensitive information on Debian LTS.
It was discovered that Twisted, a Python event-based framework for internet applications, is affected by HTTP request splitting vulnerabilities, and may expose sensitive data when ...

Summary

CVE-2020-10108

HTTP request splitting vulnerability. When presented with two
content-length headers, it ignored the first header. When the
second content-length value was set to zero, the request body was
interpreted as a pipelined request.

CVE-2020-10109

HTTP request splitting vulnerability. When presented with a
content-length and a chunked encoding header, the content-length
took precedence and the remainder of the request body was
interpreted as a pipelined request.

CVE-2022-21712

Twisted exposes cookies and authorization headers when following
cross-origin redirects. This issue is present in the
`twisted.web.RedirectAgent` and
`twisted.web.BrowserLikeRedirectAgent` functions.

For Debian 9 stretch, these problems have been fixed in version
16.6.0-2+deb9u1.

We recommend that you upgrade your twisted packages.

For the detailed security status of twisted please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: twisted
Version: 16.6.0-2+deb9u1
CVE ID: CVE-2020-10108 CVE-2020-10109 CVE-2022-21712
Debian Bug: 953950

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here