Описание
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
A flaw was found in python-ldap. The vulnerability occurs due to a regular expression and leads to a denial of service attack. This flaw allows an attacker to parse LDAP schema definitions from an untrusted source, leading to a crash or code execution.
Отчет
Red Hat Enterprise Linux 9.0.z is affected by this vulnerability as it includes the vulnerable version of python-ldap (3.3.1). However, the issue was resolved in Red Hat Enterprise Linux 9.2 and later via RHEA-2023:2359, which rebased python-ldap to version 3.4.3 containing the upstream fix. Red Hat Enterprise Linux 10 is not affected, as it does not ship the vulnerable code.
Меры по смягчению последствий
Check input for an excessive amount of backslashes in schemas. More than a dozen backslashes per line are atypical.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | python-ldap | Affected | ||
| Red Hat Ansible Tower 3 | python-ldap | Affected | ||
| Red Hat Enterprise Linux 6 | python-ldap | Out of support scope | ||
| Red Hat Enterprise Linux 7 | python-ldap | Out of support scope | ||
| Red Hat Enterprise Linux 8 | python-ldap | Will not fix | ||
| Red Hat Enterprise Linux 9 | python-ldap | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | python-ldap3 | Out of support scope | ||
| Red Hat OpenStack Platform 16.1 | python-ldap3 | Not affected | ||
| Red Hat OpenStack Platform 16.2 | python-ldap3 | Not affected | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
python-ldap before 3.4.0 is vulnerable to a denial of service when lda ...
EPSS
6.5 Medium
CVSS3