Publishing details

Changelog

twisted (18.9.0-11ubuntu0.20.04.3) focal-security; urgency=medium

  * SECURITY UPDATE: script injection via unescaped 404 response
    - debian/patches/CVE-2022-39348.patch: fix NameVirtualHost HTML
      injection vulnerability.
    - CVE-2022-39348
  * SECURITY UPDATE: Disordered HTTP pipeline response in twisted.web
    - debian/patches/CVE-2023-46137-*.patch: handle requests in raw mode.
    - CVE-2023-46137

 -- Marc Deslauriers <email address hidden>  Mon, 04 Dec 2023 09:02:22 -0500

Available diffs

Builds

Built packages

Package files