Executive Summary

Summary
Title Twisted vulnerabilities
Informations
Name USN-4308-2 First vendor Publication 2020-03-30
Vendor Ubuntu Last vendor Modification 2020-03-30
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:N)
Cvss Base Score 5.8 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in Twisted.

Software Description: - twisted: Event-based framework for internet applications

Details:

USN-4308-1 fixed several vulnerabilities in Twisted. This update provides the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

it was discovered that Twisted incorrectly validated or sanitized certain
URIs or HTTP methods. A remote attacker could use this issue to inject
invalid characters and possibly perform header injection attacks.
(CVE-2019-12387)

It was discovered that Twisted incorrectly verified XMPP TLS certificates.
A remote attacker could possibly use this issue to perform a
man-in-the-middle attack and obtain sensitive information. (CVE-2019-12855)

Jake Miller and ZeddYu Lu discovered that Twisted incorrectly handled
certain content-length headers. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2020-10108,
CVE-2020-10109)

Update instructions:

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.04 ESM:
python-twisted 13.2.0-1ubuntu1.2+esm1
python-twisted-bin 13.2.0-1ubuntu1.2+esm1
python-twisted-web 13.2.0-1ubuntu1.2+esm1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4308-2
https://usn.ubuntu.com/4308-1
CVE-2019-12387, CVE-2019-12855, CVE-2020-10108, CVE-2020-10109

Original Source

Url : http://www.ubuntu.com/usn/USN-4308-2

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
25 % CWE-295 Certificate Issues
25 % CWE-74 Failure to Sanitize Data into a Different Plane ('Injection')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 2
Os 4
Os 1
Os 3
Os 2

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2020-03-30 21:18:48
  • First insertion