Ubuntu Security Notice 6988-1 - It was discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay and manipulate responses. This issue only affected Ubuntu 24.04 LTS. It was discovered that Twisted did not properly sanitize certain input. An attacker could use this vulnerability to possibly execute an HTML injection leading to a cross-site scripting attack.
b3e9ccedfdbf38665257767f0dc668db4901ec80e4f37709d43bcb54502ddae9
==========================================================================
Ubuntu Security Notice USN-6988-1
September 04, 2024
twisted vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Twisted.
Software Description:
- twisted: Event-based framework for internet applications
Details:
It was discovered that Twisted incorrectly handled response order when
processing multiple HTTP requests. A remote attacker could possibly use
this issue to delay and manipulate responses.
This issue only affected Ubuntu 24.04 LTS. (CVE-2024-41671)
It was discovered that Twisted did not properly sanitize certain input.
An attacker could use this vulnerability to possibly execute an HTML
injection leading to a cross-site scripting (XSS) attack.
(CVE-2024-41810)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
python3-twisted 24.3.0-1ubuntu0.1
Ubuntu 22.04 LTS
python3-twisted 22.1.0-2ubuntu2.5
Ubuntu 20.04 LTS
python3-twisted 18.9.0-11ubuntu0.20.04.4
Ubuntu 18.04 LTS
python-twisted 17.9.0-2ubuntu0.3+esm1
Available with Ubuntu Pro
python3-twisted 17.9.0-2ubuntu0.3+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
python-twisted 16.0.0-1ubuntu0.4+esm2
Available with Ubuntu Pro
python3-twisted 16.0.0-1ubuntu0.4+esm2
Available with Ubuntu Pro
Ubuntu 14.04 LTS
python-twisted 13.2.0-1ubuntu1.2+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6988-1
CVE-2024-41671, CVE-2024-41810
Package Information:
https://launchpad.net/ubuntu/+source/twisted/24.3.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.5
https://launchpad.net/ubuntu/+source/twisted/18.9.0-11ubuntu0.20.04.4