python-twisted-web-12.1.0-7.el7

エラータID: AXSA:2020-025:01

Release date: 
Monday, April 27, 2020 - 05:17
Subject: 
python-twisted-web-12.1.0-7.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Twisted is an event-based framework for internet applications. Twisted Web is a complete web server, aimed at hosting web applications using Twisted and Python, but fully able to serve static pages too.

Security Fix(es):

* python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108)

* python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109)

* python-twisted: Improper neutralization of CRLF characters in URIs and HTTP methods (CVE-2019-12387)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
CVE-2020-10109
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
CVE-2019-12387
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-twisted-web-12.1.0-7.el7.src.rpm
    MD5: a3bb373521ddd3be7427a430ce25ce31
    SHA-256: 0be46b342a0d13103522a731d570fc1e2a8a4a8c17f943927f27a57cf018fb77
    Size: 394.97 kB

Asianux Server 7 for x86_64
  1. python-twisted-web-12.1.0-7.el7.x86_64.rpm
    MD5: 5bab90ec84186ebec4c3b391d333daf8
    SHA-256: 6b8a5cd5c25da79a11468dfb359a78b568abc73563981ecbf8152d885bdb4228
    Size: 727.42 kB
  2. python-twisted-web-12.1.0-7.el7.i686.rpm
    MD5: 94b2b08a2cba0093f46ba770d71a92fd
    SHA-256: 3e3a98842852d0b85d60a0ada4dff492d07b7ad9c9eade46f15eba568c91c2d8
    Size: 727.40 kB