Incorrect Regular Expression in python-py - CVE-2022-42969

 

Incorrect Regular Expression in python-py - CVE-2022-42969

Published: January 30, 2023


Vulnerability identifier: #VU71642
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-42969
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation in Subversion repository caused by a mishandled InfoSvnCommand argument. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

python-py
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise High Performance Computing
Public Cloud Module
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
IBM Cloud Pak for Data System
IBM Spectrum Protect Plus
Spectrum Discover
EMC ECS
ObjectScale
DB2 on Cloud Pak for Data
IBM Netezza for Cloud Pak for Data
Splunk Enterprise
python3-py
python-py
watsonx.data
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM

How to mitigate CVE-2022-42969

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Cloud Pak for Data System - update to 1.0.8.0
EMC ECS - update to 3.7.0.6
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
IBM Spectrum Protect Plus - update to 10.1.17.1
ObjectScale - update to 1.4.0
python3-py - addressed in versions 1.8.1-11.15.2, 1.8.1-11.18.1, 1.10.0-150100.5.12.1
python-py - addressed in versions 1.8.1-11.15.2, 1.8.1-11.18.1
watsonx.data - update to 2.0.3
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3

External References

Related Security Bulletins