Jake Miller and ZeddYu Lu discovered that Twisted incorrectly handled certain
content-length headers. A remote attacker could possibly use this issue to
perform HTTP request splitting attacks (CVE-2020-10108, CVE-2020-10109).
- https://bugs.mageia.org/show_bug.cgi?id=26355
- https://ubuntu.com/security/notices/USN-4308-1
- https://access.redhat.com/errata/RHSA-2020:1561
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YW3NIL7VXSGJND2Q4BSXM3CFTAFU6T7D/
- https://bishopfox.com/blog/twisted-version-19-10-0-advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00018.html
- https://www.cve.org/CVERecord?id=CVE-2020-10108
- https://www.cve.org/CVERecord?id=CVE-2020-10109
- 7/core/python-twisted-19.2.1-1.2.mga7
Get the latest Linux and open source security news straight to your inbox.