USN-6988-1: Twisted vulnerabilities
Ben Kallus discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay and manipulate responses. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-41671) It was discovered that Twisted did not properly sanitize certain input. An attacker could use this vulnerability to possibly execute an HTML injection leading to a cross-site scripting (XSS) attack. (CVE-2024-41810)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6988-1?
The severity of USN-6988-1 is considered medium due to potential response manipulation by remote attackers.
How do I fix USN-6988-1?
To fix USN-6988-1, you should upgrade the affected python3-twisted package to the specified remedied version for your Ubuntu release.
Which Ubuntu versions are affected by USN-6988-1?
USN-6988-1 affects Ubuntu versions 24.04, 22.04, 20.04, 18.04, 16.04, and 14.04.
How does USN-6988-1 impact Twisted users?
USN-6988-1 impacts Twisted users by potentially allowing a remote attacker to delay and manipulate HTTP responses.
Is it safe to use Twisted prior to the USN-6988-1 fix?
It is not safe to use Twisted prior to the fix for USN-6988-1 due to the risk of response manipulation vulnerabilities.