Ubuntu has issued an advisory on November 26: https://ubuntu.com/security/notices/USN-6988-1 https://ubuntu.com/security/notices/USN-6988-2 Fix: https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc
Source RPM: (none) => python-twisted-24.3.0-1.mga10.src.rpm, python-twisted-22.10.0-2.mga9.src.rpmStatus comment: (none) => Patch available from Ubuntu and upstreamWhiteboard: (none) => MGA9TOOCVE: (none) => CVE-2024-41671
Thank you again for the patch URL. Assigning to Python maintainers.
Assignee: bugsquad => python
Summary: python-twisted new security issue CVE-2024-41671 => python-twisted new security issues CVE-2024-41671 and CVE-2024-41810
CVE: CVE-2024-41671 => CVE-2024-41671, CVE-2024-41810
Summary: python-twisted new security issues CVE-2024-41671 and CVE-2024-41810 => python-twisted new security issues CVE-2023-46137, CVE-2024-41671 and CVE-2024-41810CVE: CVE-2024-41671, CVE-2024-41810 => CVE-2023-46137, CVE-2024-41671, CVE-2024-41810
Suggested advisory: ======================== The updated packages fix security vulnerabilities: Twisted.web has disordered HTTP pipeline response. (CVE-2023-46137) Twisted.web has disordered HTTP pipeline response. (CVE-2024-41671) HTML injection in HTTP redirect body. (CVE-2024-41810) References: https://ubuntu.com/security/notices/USN-6575-1 https://ubuntu.com/security/notices/USN-6988-1 https://ubuntu.com/security/notices/USN-6988-2 ======================== Updated packages in core/updates_testing: ======================== python3-twisted+tls-22.10.0-2.1.mga9 python3-twisted-22.10.0-2.1.mga9 from SRPM: python-twisted-22.10.0-2.1.mga9.src.rpm
Status comment: Patch available from Ubuntu and upstream => (none)Version: Cauldron => 9Whiteboard: MGA9TOO => (none)Source RPM: python-twisted-24.3.0-1.mga10.src.rpm, python-twisted-22.10.0-2.mga9.src.rpm => python-twisted-22.10.0-2.mga9.src.rpmStatus: NEW => ASSIGNEDAssignee: python => qa-bugs
Keywords: (none) => advisory
MGA9-64 Plasma Wayland on Compaq H000SB. No installation issues. Tried to test by opening kajong. It opens and dialogue for users can be opened. Skipped that and some playgrond opens with 3 talking robots around. They do things which I do not understand and cann't be bothered to delve into. So looking at previous bugs 30067 and 31140, this should be good enough to go.
Whiteboard: (none) => MGA9-64-OKCC: (none) => herman.viaene
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0054.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED