CVE-2022-21716
published 2022-03-03CVE-2022-21716: Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.51%
87.9th percentile
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | twisted | < twisted 22.2.0-1 (bookworm) | twisted 22.2.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| twisted | twisted | < 22.2.0 | 22.2.0 |
| twisted | twisted | >= 0 < 20.3.0-7+deb11u1 | 20.3.0-7+deb11u1 |
| twisted | twisted | >= 0 < 22.2.0-1 | 22.2.0-1 |
| twisted | twisted | >= 0 < 22.2.0-1 | 22.2.0-1 |
| twisted | twisted | >= 0 < 22.2.0-1 | 22.2.0-1 |
| twisted | twisted | >= 0 < 17.9.0-2ubuntu0.3 | 17.9.0-2ubuntu0.3 |
| twisted | twisted | >= 0 < 18.9.0-11ubuntu0.20.04.2 | 18.9.0-11ubuntu0.20.04.2 |
| twisted | twisted | >= 0 < 22.1.0-2ubuntu2.1 | 22.1.0-2ubuntu2.1 |
| twisted | twisted | >= 0 < 13.2.0-1ubuntu1.2+esm2 | 13.2.0-1ubuntu1.2+esm2 |
| twisted | twisted | >= 0 < 16.0.0-1ubuntu0.4+esm1 | 16.0.0-1ubuntu0.4+esm1 |
| twisted | twisted | >= 21.7.0 < 22.2.0 | 22.2.0 |
| twisted | twisted | >= 21.7.0 < 22.2.0 | 22.2.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Twisted vulnerability
vendor_ubuntu·2022-05-05·CVSS 7.5
CVE-2022-21716 [HIGH] Twisted vulnerability
Title: Twisted vulnerability
Summary: Twisted could be made to crash if it received specially crafted network
traffic.
USN-5354-1 fixed vulnerabilities in Twisted. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Twisted vulnerabilities
vendor_ubuntu·2022-03-30·CVSS 7.5
CVE-2022-21712 [HIGH] Twisted vulnerabilities
Title: Twisted vulnerabilities
Summary: Several security issues were fixed in Twisted.
It was discovered that Twisted incorrectly filtered HTTP headers when clients
are being redirected to another origin. A remote attacker could use this issue
to obtain sensitive information. (CVE-2022-21712)
It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-twisted: SSH client and server denial of service during SSH handshake
vendor_redhat·2022-03-03·CVSS 7.5
CVE-2022-21716 [HIGH] CWE-770 python-twisted: SSH client and server denial of service during SSH handshake
python-twisted: SSH client and server denial of service during SSH handshake
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.
An uncontrolled resource consumption flaw was found in python-twisted in the dataReceived() function. This flaw allows an unauthenticated, remote attacker to send a simple command to use all available memory and crash the server.
Package: automation-controller (Red Hat Ansible Automation P
Debian
CVE-2022-21716: twisted - Twisted is an event-based framework for internet applications, supporting Python...
vendor_debian·2022·CVSS 7.5
CVE-2022-21716 [HIGH] CVE-2022-21716: twisted - Twisted is an event-based framework for internet applications, supporting Python...
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.
Scope: local
bookworm: resolved (fixed in 22.2.0-1)
bullseye: resolved (fixed in 20.3.0-7+deb11u1)
forky: resolved (fixed in 22.2.0-1)
sid: resolved (fixed in 22.2.0-1)
trixie: resolved (fixed in 22.2.0-1)
OSV
twisted vulnerability
osv·2022-05-05·CVSS 7.5
CVE-2022-21716 [HIGH] twisted vulnerability
twisted vulnerability
USN-5354-1 fixed vulnerabilities in Twisted. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)
OSV
twisted vulnerabilities
osv·2022-03-30·CVSS 7.5
CVE-2022-21712 [HIGH] twisted vulnerabilities
twisted vulnerabilities
It was discovered that Twisted incorrectly filtered HTTP headers when clients
are being redirected to another origin. A remote attacker could use this issue
to obtain sensitive information. (CVE-2022-21712)
It was discovered that Twisted incorrectly processed SSH handshake data on
connection establishments. A remote attacker could use this issue to cause
Twisted to crash, resulting in a denial of service. (CVE-2022-21716)
OSV
CVE-2022-21716: Twisted is an event-based framework for internet applications, supporting Python 3
osv·2022-03-03·CVSS 7.5
CVE-2022-21716 [HIGH] CVE-2022-21716: Twisted is an event-based framework for internet applications, supporting Python 3
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.
GHSA
Twisted SSH client and server deny of service during SSH handshake.
ghsa·2022-03-03
CVE-2022-21716 [HIGH] CWE-120 Twisted SSH client and server deny of service during SSH handshake.
Twisted SSH client and server deny of service during SSH handshake.
### Impact
The Twisted SSH client and server implementation naively accepted an infinite amount of data for the peer's SSH version identifier.
A malicious peer can trivially craft a request that uses all available memory and crash the server, resulting in denial of service. The attack is as simple as `nc -rv localhost 22 < /dev/zero`.
### Patches
The issue was fix in GitHub commit https://github.com/twisted/twisted/commit/98387b39e9f0b21462f6abc7a1325dc370fcdeb1
A fix is available in Twisted 22.2.0.
### Workarounds
* Limit access to the SSH server only to trusted source IP addresses.
* Connect over SSH only to trusted destination IP addresses.
### References
Reported at https://twistedmatrix.com/trac/ticket/10284
OSV
Twisted SSH client and server deny of service during SSH handshake.
osv·2022-03-03
CVE-2022-21716 [HIGH] Twisted SSH client and server deny of service during SSH handshake.
Twisted SSH client and server deny of service during SSH handshake.
### Impact
The Twisted SSH client and server implementation naively accepted an infinite amount of data for the peer's SSH version identifier.
A malicious peer can trivially craft a request that uses all available memory and crash the server, resulting in denial of service. The attack is as simple as `nc -rv localhost 22 < /dev/zero`.
### Patches
The issue was fix in GitHub commit https://github.com/twisted/twisted/commit/98387b39e9f0b21462f6abc7a1325dc370fcdeb1
A fix is available in Twisted 22.2.0.
### Workarounds
* Limit access to the SSH server only to trusted source IP addresses.
* Connect over SSH only to trusted destination IP addresses.
### References
Reported at https://twistedmatrix.com/trac/ticket/10284
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/twisted/twisted/commit/89c395ee794e85a9657b112c4351417850330ef9https://github.com/twisted/twisted/releases/tag/twisted-22.2.0https://github.com/twisted/twisted/security/advisories/GHSA-rv6r-3f5q-9rgxhttps://lists.debian.org/debian-lts-announce/2022/03/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6/https://security.gentoo.org/glsa/202301-02https://twistedmatrix.com/trac/ticket/10284https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://github.com/twisted/twisted/commit/89c395ee794e85a9657b112c4351417850330ef9https://github.com/twisted/twisted/releases/tag/twisted-22.2.0https://github.com/twisted/twisted/security/advisories/GHSA-rv6r-3f5q-9rgxhttps://lists.debian.org/debian-lts-announce/2022/03/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6/https://security.gentoo.org/glsa/202301-02https://twistedmatrix.com/trac/ticket/10284https://www.oracle.com/security-alerts/cpuapr2022.html
2022-03-03
Published