GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Jul 27, 2020 10:26 pm Post subject: [ GLSA 202007-24 ] Twisted |
|
|
Gentoo Linux Security Advisory
Title: Twisted: Access restriction bypasses (GLSA 202007-24)
Severity: normal
Exploitable: remote
Date: 2020-07-27
Bug(s): #712240
ID: 202007-24
Synopsis
Multiple vulnerabilities have been found in Twisted, the worst of
which could result in a Denial of Service condition.
Background
Twisted is an asynchronous networking framework written in Python.
Affected Packages
Package: dev-python/twisted
Vulnerable: < 20.3.0
Unaffected: >= 20.3.0
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Twisted. Please review
the CVE identifiers referenced below for details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Twisted users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-python/twisted-20.3.0"
|
References
CVE-2020-10108
CVE-2020-10109 |
|