Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8wq-qrxc-hmcm

Опубликовано: 29 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

ReDoS in LDAP schema parser

https://github.com/python-ldap/python-ldap/issues/424

Impact

The LDAP schema parser of python-ldap 3.3.1 and earlier are vulnerable to a regular expression denial-of-service attack. The issue affects clients that use ldap.schema package to parse LDAP schema definitions from an untrusted source.

Patches

The upcoming release of python-ldap 3.4.0 will contain a workaround to prevent ReDoS attacks. The schema parser refuses schema definitions with an excessive amount of backslashes.

Workarounds

As a workaround, users can check input for excessive amount of backslashes in schemas. More than a dozen backslashes per line are atypical.

References

CWE-1333

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

python-ldap

pip
Затронутые версииВерсия исправления

< 3.4.0

3.4.0

6.5 Medium

CVSS3

Дефекты

CWE-1333

6.5 Medium

CVSS3

Дефекты

CWE-1333