=========================================================================Ubuntu Security Notice USN-5354-2
May 05, 2022

twisted vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Twisted could be made to crash if it received specially crafted network
traffic.

Software Description:
- twisted: Event-based framework for internet applications

Details:

USN-5354-1 fixed vulnerabilities in Twisted. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 22.04 LTS.

Original advisory details:
  It was discovered that Twisted incorrectly processed SSH handshake data on
  connection establishments. A remote attacker could use this issue to cause
  Twisted to crash, resulting in a denial of service. (CVE-2022-21716)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
python3-twisted 22.1.0-2ubuntu2.1

Ubuntu 16.04 ESM:
python-twisted 16.0.0-1ubuntu0.4+esm1
python-twisted-bin 16.0.0-1ubuntu0.4+esm1
python-twisted-web 16.0.0-1ubuntu0.4+esm1
python3-twisted 16.0.0-1ubuntu0.4+esm1

Ubuntu 14.04 ESM:
python-twisted 13.2.0-1ubuntu1.2+esm2
python-twisted-bin 13.2.0-1ubuntu1.2+esm2
python-twisted-web 13.2.0-1ubuntu1.2+esm2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5354-2
https://ubuntu.com/security/notices/USN-5354-1
CVE-2022-21716

Package Information:
https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.1

Ubuntu 5354-2: Twisted vulnerability

May 5, 2022
Twisted could be made to crash if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-twisted 22.1.0-2ubuntu2.1 Ubuntu 16.04 ESM: python-twisted 16.0.0-1ubuntu0.4+esm1 python-twisted-bin 16.0.0-1ubuntu0.4+esm1 python-twisted-web 16.0.0-1ubuntu0.4+esm1 python3-twisted 16.0.0-1ubuntu0.4+esm1 Ubuntu 14.04 ESM: python-twisted 13.2.0-1ubuntu1.2+esm2 python-twisted-bin 13.2.0-1ubuntu1.2+esm2 python-twisted-web 13.2.0-1ubuntu1.2+esm2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5354-2

https://ubuntu.com/security/notices/USN-5354-1

CVE-2022-21716

Severity
May 05, 2022

Package Information

https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.1

Related News