Resource exhaustion in httplib2 - CVE-2021-21240
Published: February 28, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion by tricking the application to connect to a malicious server that responds with long series of "xa0" characters in the "www-authenticate" header.
Affected software
Arch Linux
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Module for Basesystem
openEuler
SUSE Linux Enterprise Module for Packagehub Subpackages
python-httplib2 (Red Hat package)
python-httplib2
python2-httplib2
python3-httplib2
Red Hat OpenStack
How to mitigate CVE-2021-21240
python-httplib2 (Red Hat package) - update to 0.13.1-2.el8ost
python-httplib2 - update to 0.19.0-1
python2-httplib2 - update to 0.19.0-1
python3-httplib2 - update to 0.19.0-1
python3-httplib2 - addressed in versions 0.19.0-1.8.1, 0.19.0-3.3.1
python2-httplib2 - update to 0.19.0-3.3.1
python-httplib2 - addressed in versions 0.19.0-7.3.1, 0.19.0-7.7.1, 0.19.0-8.3.4
Red Hat OpenStack - update to 16.1.6
External References
Related Security Bulletins
- Denial of service in httplib2
- Arch Linux update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- SUSE update for python-httplib2
- openEuler update for python-httplib2
- Multiple vulnerabilities in Red Hat OpenStack 16.1 packages