Resource exhaustion in httplib2 - CVE-2021-21240

 

Resource exhaustion in httplib2 - CVE-2021-21240

Published: February 28, 2021


Vulnerability identifier: #VU50989
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21240
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion by tricking the application to connect to a malicious server that responds with long series of "xa0" characters in the "www-authenticate" header.


Affected software

httplib2
Arch Linux
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
python-httplib2 (Red Hat package)
python-httplib2
python2-httplib2
python3-httplib2
Red Hat OpenStack

How to mitigate CVE-2021-21240

Install updates from vendor's website.

httplib2 - update to 0.19.0
python-httplib2 (Red Hat package) - update to 0.13.1-2.el8ost
python-httplib2 - update to 0.19.0-1
python2-httplib2 - update to 0.19.0-1
python3-httplib2 - update to 0.19.0-1
python3-httplib2 - addressed in versions 0.19.0-1.8.1, 0.19.0-3.3.1
python2-httplib2 - update to 0.19.0-3.3.1
python-httplib2 - addressed in versions 0.19.0-7.3.1, 0.19.0-7.7.1, 0.19.0-8.3.4
Red Hat OpenStack - update to 16.1.6

External References

Related Security Bulletins