Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-49769

Опубликовано: 29 окт. 2024
Источник: redhat
CVSS3: 7.5

Описание

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer exists, but not removing it from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could run waitress out of available sockets with very little resources required. Waitress 3.0.1 contains fixes that remove the race condition.

A flaw was found in the Waitress WSGI server for Python. When a remote client closes the connection before waitress has had the opportunity to call getpeername(), waitress will incorrectly clean up the connection, leading to the main thread attempting to write to a socket that no longer exists, and that socket is not removed from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could exhaust the available sockets with very little resources required.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 4python-waitressAffected
Red Hat Ceph Storage 5python-waitressAffected
Red Hat Openshift Container Storage 4python-waitressAffected
Ironic content for Red Hat OpenShift Container Platform 4.12python-waitressFixedRHSA-2024:1053505.12.2024
Ironic content for Red Hat OpenShift Container Platform 4.13python-waitressFixedRHSA-2024:1081512.12.2024
Red Hat OpenShift Container Platform 4.14python-waitressFixedRHSA-2024:962320.11.2024
Red Hat OpenShift Container Platform 4.15python-waitressFixedRHSA-2024:1014526.11.2024
Red Hat OpenShift Container Platform 4.16python-waitressFixedRHSA-2024:961820.11.2024
Red Hat OpenShift Container Platform 4.17python-waitressFixedRHSA-2024:961319.11.2024
Red Hat OpenStack Platform 16.2python-waitressFixedRHSA-2025:020109.01.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2322461waitress: Waitress has a denial of service leading to high CPU usage/resource exhaustion

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer exists, but not removing it from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could run waitress out of available sockets with very little resources required. Waitress 3.0.1 contains fixes that remove the race condition.

CVSS3: 7.5
nvd
около 1 года назад

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitress won't correctly clean up the connection leading to the main thread attempting to write to a socket that no longer exists, but not removing it from the list of sockets to attempt to process. This leads to a busy-loop calling the write function. A remote attacker could run waitress out of available sockets with very little resources required. Waitress 3.0.1 contains fixes that remove the race condition.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
около 1 года назад

Waitress is a Web Server Gateway Interface server for Python 2 and 3. ...

suse-cvrf
около 1 года назад

Security update for python-waitress

7.5 High

CVSS3