it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5797-1] twisted security update
- Date: Fri, 25 Oct 2024 18:12:54 +0000
- Authentication-results: lists.piratenpartei.de; dkim=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/ZxvfpkWQ/o32HkLK AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=Z6cYBtDyau6LX4WBLEqOZys5pYupPHYlZLPIcZ1rH4w=; b=Qw 6YA4HWS9I39yFP7RP/YVCmPpR+rX2tpvA1C997IaUV83eKbjmBzSrFy5JtcKzP0E47J4YuDpjf1uE YRPz/LFw3+F8EklNx+gCjN/gQn93bUBxjMU8hLbuCYUs2EvaQB7yjKS4tivUSUeb3ZRVlxkRJfDVz KoG8GtDRGKFAkq64c1lqRAAyrtFGmpHv4ycEXHMzkPj195RylvAFQxpWmqgqc+2MyekJ4Qv9Po/di 4GUX+dmY4keutqBTf0rrePwJ9fjJ7TTY4aICvMbBx5BL6KuVZOvQbu/0ud2uVZjzkyIwTC9+KfeFh /vE6W4NbpLaRTdHq/ix4MNKoGYPJr66g==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Fri, 25 Oct 2024 18:13:43 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <_BIXctiBJwP.A.5yzI.X_9GnB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5797-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
October 25, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : twisted
CVE ID : CVE-2023-46137 CVE-2024-41671 CVE-2024-41810
Multiple security issues were found in Twisted, an event-based framework
for internet applications, which could result in incorrect ordering of
HTTP requests or cross-site scripting.
For the stable distribution (bookworm), these problems have been fixed in
version 22.4.0-4+deb12u1.
We recommend that you upgrade your twisted packages.
For the detailed security status of twisted please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/twisted
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmcb3uEACgkQEMKTtsN8
TjZEtw//VpqsmdlkvjKnR1rYRjoopuH1cx5lSdB5u7EoXGiSKTp9Dt5l2Q44fl+P
i2uLjO/IX5ZbtiWDeNvBoFYfaqvHBlv680WiaUnmvTzPuovB2fT5Q7ZOdI7SH5y2
yhYpmaapZSb2kRYgcFO38Vi3M1LxU60t7lSXd3F5+6BopPEBRT9q0nwHAPB8NSvh
C/VQQa9BejPIggJD1koYxJlQz76VhAi3c7W60ySRk2YKQryYdyZwdpsvrrz0G05n
wZO+f6tXVihehGT2rv5OpfwGmcHZ/iwxY/IFpywdkrsnx1mV2NGVZw3t2JQYl7r/
Vs3XLg4C3Zx2NLzZgBp007ZG4vz2f4LmEe9M+bYI8NgCAzPRUJg2T4+ZoD09Dmml
k/yo+ihBxSef3H5nDkiO9a4OsEQzk74o1Hlg1ZbiUqk/7BdSar92LszlzuJVXqpA
HVtIIlUwkS+L6Z+O2iYhSBUTumrrrbRsdoo00uvHWeGOw1VmRZKYdMpoxX2St60B
RUdBZuIHlcw5qoymiIDOI/fgykCtdAbdCWj/GE6AGO4i7scOj8u8deqh/N5kKNzd
ijjkzmEQvd7e3/VSEVfBc+4CJHUMKVELaNDGflaneWxXpHLmz/pu2hwNoPw2XL9X
1bVzvph3A+Yl+oXLZUJkrELuo9Rmnv7qJ9MS9QnOpHyw0KFgEsQ=
=faBY
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5797-1] twisted security update, Moritz Muehlenhoff, 25.10.2024
Archiv bereitgestellt durch MHonArc 2.6.19+.