Описание
Security update for python-py
This update for python-py fixes the following issues:
- CVE-2020-29651: Fixed regular expression denial of service in svnwc.py (bsc#1179805, bsc#1184505).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Список пакетов
openSUSE Leap 15.2
python2-py-1.8.1-lp152.2.6.1
python3-py-1.8.1-lp152.2.6.1
Ссылки
- E-Mail link for openSUSE-SU-2021:0851-1
- SUSE Security Ratings
- SUSE Bug 1179805
- SUSE Bug 1184505
- SUSE CVE CVE-2020-29651 page
Описание
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
Затронутые продукты
openSUSE Leap 15.2:python2-py-1.8.1-lp152.2.6.1
openSUSE Leap 15.2:python3-py-1.8.1-lp152.2.6.1
Ссылки
- CVE-2020-29651
- SUSE Bug 1179805