python-twisted-web-8.2.0-6.AXS4
エラータID: AXSA:2020-036:02
Twisted is an event-based framework for internet applications. Twisted Web is a complete web server, aimed at hosting web applications using Twisted and Python, but fully able to serve static pages too.
Security Fix(es):
* python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2020-10108
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
Update packages.
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
N/A
SRPMS
- python-twisted-web-8.2.0-6.AXS4.src.rpm
MD5: 7a2d1afc16956b0675cec8d81d530e00
SHA-256: ed9a4a02940a1b4c213ad949a0b2bcd4a902f88faf4079fd5d1996f8ee15fb38
Size: 335.40 kB
Asianux Server 4 for x86
- python-twisted-web-8.2.0-6.AXS4.i686.rpm
MD5: cc9a356fcba57cfded5ccad2ada85872
SHA-256: c19053ccc199ea1021ddf2a7325687c208a7d2d0427cf52fbf3e1de77b8ee0c9
Size: 635.97 kB
Asianux Server 4 for x86_64
- python-twisted-web-8.2.0-6.AXS4.x86_64.rpm
MD5: 884475f495cf905bb7f339fc236c4fcf
SHA-256: 69fc26a9f860e3e682a2b35276ce368123ba785440d314796a1eeee1a30b5c3b
Size: 635.56 kB