Debian LTS Advisory DLA-2991-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                       Stefano Rivera
May 03, 2022                                  https://wiki.debian.org/LTS

Package        : twisted
Version        : 16.6.0-2+deb9u3
CVE ID         : CVE-2022-24801
Debian Bug     : 1009030

The Twisted Web HTTP 1.1 server, located in the twisted.web.http module, parsed
several HTTP request constructs more leniently than permitted by RFC 7230. This
non-conformant parsing can lead to desync if requests pass through multiple
HTTP parsers, potentially resulting in HTTP request smuggling.

For Debian 9 stretch, this problem has been fixed in version

We recommend that you upgrade your twisted packages.

For the detailed security status of twisted please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2991-1: twisted security update

May 3, 2022
The Twisted Web HTTP 1.1 server, located in the twisted.web.http module, parsed several HTTP request constructs more leniently than permitted by RFC 7230


For Debian 9 stretch, this problem has been fixed in version

We recommend that you upgrade your twisted packages.

For the detailed security status of twisted please refer to
its security tracker page at:

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Package : twisted
Version : 16.6.0-2+deb9u3
CVE ID : CVE-2022-24801
Debian Bug : 1009030

Related News