Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-29651

Опубликовано: 03 сент. 2020
Источник: redhat
CVSS3: 4.3

Описание

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-py package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-pyOut of support scope
Red Hat Enterprise Linux 8python27:2.7/python-pyFix deferred
Red Hat Enterprise Linux 8python-pyFix deferred
Red Hat Enterprise Linux 9python-pyNot affected
Red Hat OpenShift Container Platform 3.11python-pyFix deferred
Red Hat OpenStack Platform 10 (Newton)python-pyOut of support scope
Red Hat OpenStack Platform 13 (Queens)python-pyWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1906451python-py: ReDoS in the py.path.svnwc component via mailicious input to blame functionality

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

CVSS3: 7.5
nvd
около 5 лет назад

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

CVSS3: 7.5
msrc
около 5 лет назад

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

CVSS3: 7.5
debian
около 5 лет назад

A denial of service via regular expression in the py.path.svnwc compon ...

suse-cvrf
больше 4 лет назад

Security update for python-py

4.3 Medium

CVSS3