python-twisted-web-8.2.0-6.AXS4

エラータID: AXSA:2020-036:02

Release date: 
Wednesday, April 29, 2020 - 12:45
Subject: 
python-twisted-web-8.2.0-6.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Twisted is an event-based framework for internet applications. Twisted Web is a complete web server, aimed at hosting web applications using Twisted and Python, but fully able to serve static pages too.

Security Fix(es):

* python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-twisted-web-8.2.0-6.AXS4.src.rpm
    MD5: 7a2d1afc16956b0675cec8d81d530e00
    SHA-256: ed9a4a02940a1b4c213ad949a0b2bcd4a902f88faf4079fd5d1996f8ee15fb38
    Size: 335.40 kB

Asianux Server 4 for x86
  1. python-twisted-web-8.2.0-6.AXS4.i686.rpm
    MD5: cc9a356fcba57cfded5ccad2ada85872
    SHA-256: c19053ccc199ea1021ddf2a7325687c208a7d2d0427cf52fbf3e1de77b8ee0c9
    Size: 635.97 kB

Asianux Server 4 for x86_64
  1. python-twisted-web-8.2.0-6.AXS4.x86_64.rpm
    MD5: 884475f495cf905bb7f339fc236c4fcf
    SHA-256: 69fc26a9f860e3e682a2b35276ce368123ba785440d314796a1eeee1a30b5c3b
    Size: 635.56 kB