Updated python-twisted packages fix security vulnerabilities: Improper sanitization of URIs or HTTP which could allow attackers to perform CRLF attacks (CVE-2019-12387). . MGASA-2019-0360 - Updated python-twisted packages fix security vulnerabilities Publication date: 06 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0360.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12387, CVE-2019-12855 Updated python-twisted packages fix security vulnerabilities: Improper sanitization of URIs or HTTP which could allow attackers to perform CRLF attacks (CVE-2019-12387). In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections (CVE-2019-12855). References: - https://bugs.mageia.org/show_bug.cgi?id=25752 - - - https://www.cve.org/CVERecord?id=CVE-2019-12387 - https://www.cve.org/CVERecord?id=CVE-2019-12855 SRPMS: - 7/core/python-twisted-19.2.1-1.1.mga7 . Recent enhancements in python-twisted libraries address URI validation concerns, effectively mitigating risks associated with CRLF and man-in-the-middle threats.. Mageia Security Update, python-twisted Package Fix, MITM Attack Prevention. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.