Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-32839

Опубликовано: 20 сент. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

РелизСтатусПримечание
bionic

not-affected

0.2.4-0.1
devel

released

0.4.1-1ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

0.2.4-0.1
esm-infra/focal

not-affected

0.2.4-3
esm-infra/xenial

not-affected

focal

not-affected

0.2.4-3
hirsute

released

0.4.1-1ubuntu0.1
impish

released

0.4.1-1ubuntu1
jammy

released

0.4.1-1ubuntu1

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 4 лет назад

sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

CVSS3: 7.5
nvd
больше 4 лет назад

sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sqlparse vulnerability. The regular expression may cause exponential backtracking on strings containing many repetitions of '\r\n' in SQL comments. Only the formatting feature that removes comments from SQL statements is affected by this regular expression. As a workaround don't use the sqlformat.format function with keyword strip_comments=True or the --strip-comments command line flag when using the sqlformat command line tool. The issues has been fixed in sqlparse 0.4.2.

CVSS3: 7.5
debian
больше 4 лет назад

sqlparse is a non-validating SQL parser module for Python. In sqlparse ...

suse-cvrf
около 4 лет назад

Security update for python-sqlparse

suse-cvrf
около 4 лет назад

Security update for python-sqlparse

5 Medium

CVSS2

7.5 High

CVSS3