Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5354-2

Ubuntu Security Notice 5354-2 - USN-5354-1 fixed vulnerabilities in Twisted. This update provides the corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 22.04 LTS. It was discovered that Twisted incorrectly processed SSH handshake data on connection establishments. A remote attacker could use this issue to cause Twisted to crash, resulting in a denial of service.

Packet Storm
#vulnerability#web#ubuntu#dos#ssh

==========================================================================
Ubuntu Security Notice USN-5354-2
May 05, 2022

twisted vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 22.04 LTS
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Summary:

Twisted could be made to crash if it received specially crafted network
traffic.

Software Description:

  • twisted: Event-based framework for internet applications

Details:

USN-5354-1 fixed vulnerabilities in Twisted. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 22.04 LTS.

Original advisory details:
It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
python3-twisted 22.1.0-2ubuntu2.1

Ubuntu 16.04 ESM:
python-twisted 16.0.0-1ubuntu0.4+esm1
python-twisted-bin 16.0.0-1ubuntu0.4+esm1
python-twisted-web 16.0.0-1ubuntu0.4+esm1
python3-twisted 16.0.0-1ubuntu0.4+esm1

Ubuntu 14.04 ESM:
python-twisted 13.2.0-1ubuntu1.2+esm2
python-twisted-bin 13.2.0-1ubuntu1.2+esm2
python-twisted-web 13.2.0-1ubuntu1.2+esm2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5354-2
https://ubuntu.com/security/notices/USN-5354-1
CVE-2022-21716

Package Information:
https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.1

Packet Storm: Latest News

Grav CMS 1.7.44 Server-Side Template Injection