Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0851-1

Опубликовано: 07 июн. 2021
Источник: suse-cvrf

Описание

Security update for python-py

This update for python-py fixes the following issues:

  • CVE-2020-29651: Fixed regular expression denial of service in svnwc.py (bsc#1179805, bsc#1184505).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Список пакетов

openSUSE Leap 15.2
python2-py-1.8.1-lp152.2.6.1
python3-py-1.8.1-lp152.2.6.1

Описание

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.


Затронутые продукты
openSUSE Leap 15.2:python2-py-1.8.1-lp152.2.6.1
openSUSE Leap 15.2:python3-py-1.8.1-lp152.2.6.1

Ссылки