Total vulnerabilities in the database
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as nc -rv localhost 22 < /dev/zero
. A patch is available in version 22.2.0. There are currently no known workarounds.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 9.0 | 9.0.x |
oracle / http_server | 12.2.1.3.0 | 12.2.1.3.0.x |
oracle / http_server | 12.2.1.4.0 | 12.2.1.4.0.x |
oracle / zfs_storage_appliance_kit | 8.8 | 8.8.x |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
![]() |
21.7.0 | 22.2.0 |
twisted / twisted | 21.7.0 | 22.2.0 |