Synopsis
Important: python-twisted-web security update
Type/Severity
Security Advisory: Important
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for python-twisted-web is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Twisted is an event-based framework for internet applications. Twisted Web is a complete web server, aimed at hosting web applications using Twisted and Python, but fully able to serve static pages too.
Security Fix(es):
- python-twisted: HTTP request smuggling when presented with two Content-Length headers (CVE-2020-10108)
- python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header (CVE-2020-10109)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux Server 7 x86_64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
-
Red Hat Enterprise Linux Workstation 7 x86_64
-
Red Hat Enterprise Linux Desktop 7 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 7 s390x
-
Red Hat Enterprise Linux for Power, big endian 7 ppc64
-
Red Hat Enterprise Linux for Scientific Computing 7 x86_64
-
Red Hat Enterprise Linux for Power, little endian 7 ppc64le
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
-
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le
Fixes
-
BZ - 1813439
- CVE-2020-10108 python-twisted: HTTP request smuggling when presented with two Content-Length headers
-
BZ - 1813447
- CVE-2020-10109 python-twisted: HTTP request smuggling when presented with a Content-Length and a chunked Transfer-Encoding header
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux Server 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
x86_64 |
python-twisted-web-12.1.0-7.el7_8.x86_64.rpm
|
SHA-256: a9b78295faddb0754b5be9311a4ba18eb31b0a72895a9d73230ee49336301d7b |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
x86_64 |
python-twisted-web-12.1.0-7.el7_8.x86_64.rpm
|
SHA-256: a9b78295faddb0754b5be9311a4ba18eb31b0a72895a9d73230ee49336301d7b |
Red Hat Enterprise Linux Workstation 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
x86_64 |
python-twisted-web-12.1.0-7.el7_8.x86_64.rpm
|
SHA-256: a9b78295faddb0754b5be9311a4ba18eb31b0a72895a9d73230ee49336301d7b |
Red Hat Enterprise Linux Desktop 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
x86_64 |
python-twisted-web-12.1.0-7.el7_8.x86_64.rpm
|
SHA-256: a9b78295faddb0754b5be9311a4ba18eb31b0a72895a9d73230ee49336301d7b |
Red Hat Enterprise Linux for IBM z Systems 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
s390x |
python-twisted-web-12.1.0-7.el7_8.s390x.rpm
|
SHA-256: 6b2871ade27dce8aa7f0fba75df21998ca45fa091c8f9fafd8b73d3e05d5080c |
Red Hat Enterprise Linux for Power, big endian 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
ppc64 |
python-twisted-web-12.1.0-7.el7_8.ppc64.rpm
|
SHA-256: 2652ac79772cf36081f0c59c254dcd683a9fa6c1509de5067e1053f45b8074f4 |
Red Hat Enterprise Linux for Scientific Computing 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
x86_64 |
python-twisted-web-12.1.0-7.el7_8.x86_64.rpm
|
SHA-256: a9b78295faddb0754b5be9311a4ba18eb31b0a72895a9d73230ee49336301d7b |
Red Hat Enterprise Linux for Power, little endian 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
ppc64le |
python-twisted-web-12.1.0-7.el7_8.ppc64le.rpm
|
SHA-256: 51bb25382d9aaec6b1ea734ebb12aa58d0f31ce456c2cabf0f0872c022422d37 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
s390x |
python-twisted-web-12.1.0-7.el7_8.s390x.rpm
|
SHA-256: 6b2871ade27dce8aa7f0fba75df21998ca45fa091c8f9fafd8b73d3e05d5080c |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
ppc64 |
python-twisted-web-12.1.0-7.el7_8.ppc64.rpm
|
SHA-256: 2652ac79772cf36081f0c59c254dcd683a9fa6c1509de5067e1053f45b8074f4 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7
SRPM |
python-twisted-web-12.1.0-7.el7_8.src.rpm
|
SHA-256: ed8eeaba192888efe948da04b1ba4591865a3f91d2f4935b2754e5026bef95ca |
ppc64le |
python-twisted-web-12.1.0-7.el7_8.ppc64le.rpm
|
SHA-256: 51bb25382d9aaec6b1ea734ebb12aa58d0f31ce456c2cabf0f0872c022422d37 |