Bug 1204364 (CVE-2022-42969) - VUL-0: CVE-2022-42969: python-py: ReDoS via a Subversion repository with crafted info data
Summary: VUL-0: CVE-2022-42969: python-py: ReDoS via a Subversion repository with craf...
Status: RESOLVED FIXED
Alias: CVE-2022-42969
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/345306/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-42969:6.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2022-10-17 08:28 UTC by Thomas Leroy
Modified: 2024-06-13 15:44 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-10-17 08:28:59 UTC
CVE-2022-42969

The py library through 1.11.0 for Python allows remote attackers to conduct a
ReDoS (Regular expression Denial of Service) attack via a Subversion repository
with crafted info data, because the InfoSvnCommand argument is mishandled.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-42969
https://www.cve.org/CVERecord?id=CVE-2022-42969
https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316
https://github.com/pytest-dev/py/issues/287
http://www.cvedetails.com/cve/CVE-2022-42969/
https://pypi.org/project/py
Comment 1 Thomas Leroy 2022-10-17 08:30:03 UTC
Still no plan to fix this upstream:

Regarding the CVSS, we would need to fix:
- SUSE:SLE-12-SP1:Update
- SUSE:SLE-12-SP2:Update
- SUSE:SLE-15-SP1:Update
Comment 2 Thomas Leroy 2022-12-30 08:38:20 UTC
Any news @Ciaran and @Steven? :)
Comment 6 Swamp Workflow Management 2023-01-26 20:27:22 UTC
SUSE-SU-2023:0161-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1204364
CVE References: CVE-2022-42969
JIRA References: 
Sources used:
openSUSE Leap Micro 5.3 (src):    python-py-1.10.0-150100.5.12.1
openSUSE Leap Micro 5.2 (src):    python-py-1.10.0-150100.5.12.1
openSUSE Leap 15.4 (src):    python-py-1.10.0-150100.5.12.1
SUSE Linux Enterprise Realtime Extension 15-SP3 (src):    python-py-1.10.0-150100.5.12.1
SUSE Linux Enterprise Module for Basesystem 15-SP4 (src):    python-py-1.10.0-150100.5.12.1
SUSE Linux Enterprise Micro 5.3 (src):    python-py-1.10.0-150100.5.12.1
SUSE Linux Enterprise Micro 5.2 (src):    python-py-1.10.0-150100.5.12.1
SUSE Linux Enterprise Micro 5.1 (src):    python-py-1.10.0-150100.5.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2023-02-13 14:28:58 UTC
SUSE-SU-2023:0395-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1204364
CVE References: CVE-2022-42969
JIRA References: 
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    python-py-1.8.1-11.15.2
SUSE Linux Enterprise Server 12-SP5 (src):    python-py-1.8.1-11.15.2
SUSE Linux Enterprise Module for Public Cloud 12 (src):    python-py-1.8.1-11.15.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Maintenance Automation 2023-03-08 20:30:03 UTC
SUSE-SU-2023:0681-1: An update that solves one vulnerability and has one fix can now be installed.

Category: security (moderate)
Bug References: 1204364, 1208181
CVE References: CVE-2022-42969
Sources used:
Public Cloud Module 12 (src): python-py-1.8.1-11.18.1
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): python-py-1.8.1-11.18.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): python-py-1.8.1-11.18.1
SUSE Linux Enterprise Server 12 SP5 (src): python-py-1.8.1-11.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): python-py-1.8.1-11.18.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 OBSbugzilla Bot 2023-09-06 21:55:09 UTC
This is an autogenerated message for OBS integration:
This bug (1204364) was mentioned in
https://build.opensuse.org/request/show/1109354 Factory / python-py
Comment 16 Robert Frohl 2024-04-19 14:30:55 UTC
done