Buffer overflow in Twisted Web - CVE-2022-21716

 

Buffer overflow in Twisted Web - CVE-2022-21716

Published: March 4, 2022


Vulnerability identifier: #VU61017
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21716
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.


Affected software

Twisted Web
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Fedora
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack for IBM Power
Red Hat OpenStack
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted (Red Hat package)
python-Twisted
python-Twisted-debugsource
python-Twisted-debuginfo
python-twisted-bin (Ubuntu package)
python-twisted (Ubuntu package)
python-twisted-web (Ubuntu package)
python3-twisted (Ubuntu package)
python3-twisted-bin (Ubuntu package)
python-twisted
python3-Twisted
python2-Twisted-debuginfo
python2-Twisted
python3-Twisted-debuginfo
python-Twisted-doc
python3-twisted
python-twisted-help
dev-python/twisted
Red Hat OpenStack Director Deployment Tools

How to mitigate CVE-2022-21716

Install updates from vendor's website.

Twisted Web - update to 22.2.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.9
python-twisted (Red Hat package) - update to 16.4.1-19.el8ost
python-Twisted - update to 15.2.1-9.17.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-twisted-bin (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted-web (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python3-twisted (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1, 22.1.0-2ubuntu2.1
python3-twisted-bin (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1
python-twisted - addressed in versions 19.10.0-4.el8, 22.4.0-1.fc35, 22.4.0-1.fc36, 22.4.0-1.fc37
python3-Twisted - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python2-Twisted - update to 19.10.0-150200.3.12.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python-Twisted-doc - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python3-twisted - update to 22.4.0-1
python-twisted-help - update to 22.4.0-1
python-twisted - update to 22.4.0-1
python-twisted - update to 22.4.0-124
dev-python/twisted - update to 22.10.0

External References

Related Security Bulletins