Buffer overflow in Twisted Web - CVE-2022-21716
Published: March 4, 2022
Vulnerability identifier: #VU61017
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21716
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.
Affected software
Twisted Web
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Fedora
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack for IBM Power
Red Hat OpenStack
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted (Red Hat package)
python-Twisted
python-Twisted-debugsource
python-Twisted-debuginfo
python-twisted-bin (Ubuntu package)
python-twisted (Ubuntu package)
python-twisted-web (Ubuntu package)
python3-twisted (Ubuntu package)
python3-twisted-bin (Ubuntu package)
python-twisted
python3-Twisted
python2-Twisted-debuginfo
python2-Twisted
python3-Twisted-debuginfo
python-Twisted-doc
python3-twisted
python-twisted-help
dev-python/twisted
Red Hat OpenStack Director Deployment Tools
Amazon Linux AMI
Gentoo Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Fedora
Oracle Solaris
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack for IBM Power
Red Hat OpenStack
SUSE Linux Enterprise Module for Packagehub Subpackages
python-twisted (Red Hat package)
python-Twisted
python-Twisted-debugsource
python-Twisted-debuginfo
python-twisted-bin (Ubuntu package)
python-twisted (Ubuntu package)
python-twisted-web (Ubuntu package)
python3-twisted (Ubuntu package)
python3-twisted-bin (Ubuntu package)
python-twisted
python3-Twisted
python2-Twisted-debuginfo
python2-Twisted
python3-Twisted-debuginfo
python-Twisted-doc
python3-twisted
python-twisted-help
dev-python/twisted
Red Hat OpenStack Director Deployment Tools
How to mitigate CVE-2022-21716
Install updates from vendor's website.
Twisted Web - update to 22.2.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.9
python-twisted (Red Hat package) - update to 16.4.1-19.el8ost
python-Twisted - update to 15.2.1-9.17.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-twisted-bin (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted-web (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python3-twisted (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1, 22.1.0-2ubuntu2.1
python3-twisted-bin (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1
python-twisted - addressed in versions 19.10.0-4.el8, 22.4.0-1.fc35, 22.4.0-1.fc36, 22.4.0-1.fc37
python3-Twisted - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python2-Twisted - update to 19.10.0-150200.3.12.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python-Twisted-doc - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python3-twisted - update to 22.4.0-1
python-twisted-help - update to 22.4.0-1
python-twisted - update to 22.4.0-1
python-twisted - update to 22.4.0-124
dev-python/twisted - update to 22.10.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.9
python-twisted (Red Hat package) - update to 16.4.1-19.el8ost
python-Twisted - update to 15.2.1-9.17.1
python-Twisted-debugsource - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-Twisted-debuginfo - addressed in versions 15.2.1-9.17.1, 19.10.0-150200.3.12.1
python-twisted-bin (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python-twisted-web (Ubuntu package) - update to 17.9.0-2ubuntu0.3
python3-twisted (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1, 22.1.0-2ubuntu2.1
python3-twisted-bin (Ubuntu package) - addressed in versions 17.9.0-2ubuntu0.3, 18.9.0-11ubuntu0.20.04.2, 20.3.0-7ubuntu1.1
python-twisted - addressed in versions 19.10.0-4.el8, 22.4.0-1.fc35, 22.4.0-1.fc36, 22.4.0-1.fc37
python3-Twisted - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python2-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python2-Twisted - update to 19.10.0-150200.3.12.1
python3-Twisted-debuginfo - update to 19.10.0-150200.3.12.1
python-Twisted-doc - addressed in versions 19.10.0-150200.3.12.1, 22.2.0-150400.5.4.1
python3-twisted - update to 22.4.0-1
python-twisted-help - update to 22.4.0-1
python-twisted - update to 22.4.0-1
python-twisted - update to 22.4.0-124
dev-python/twisted - update to 22.10.0
External References
Related Security Bulletins
- Denial of service in Twisted
- Red Hat OpenStack Platform 16.1 update for python-twisted
- Red Hat OpenStack Platform 16.2 update for python-twisted
- Ubuntu update for twisted
- Multiple vulnerabilities in Oracle Solaris
- Ubuntu update for twisted
- Denial of service in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Amazon Linux AMI update for python-twisted-conch
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- SUSE update for python-Twisted
- Gentoo update for Twisted
- Fedora EPEL 8 update for python-twisted
- openEuler 20.03 LTS SP3 update for python-twisted
- openEuler 22.03 LTS update for python-twisted
- openEuler 20.03 LTS SP4 update for python-twisted
- Amazon Linux AMI update for python-twisted
- Fedora 37 update for python-twisted
- Fedora 36 update for python-twisted
- Fedora 35 update for python-twisted