Incorrect Regular Expression in python-py - CVE-2022-42969
Published: January 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in Subversion repository caused by a mishandled InfoSvnCommand argument. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Linux Enterprise High Performance Computing
Public Cloud Module
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
IBM Cloud Pak for Data System
IBM Spectrum Protect Plus
Spectrum Discover
EMC ECS
ObjectScale
DB2 on Cloud Pak for Data
IBM Netezza for Cloud Pak for Data
Splunk Enterprise
python3-py
python-py
watsonx.data
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
How to mitigate CVE-2022-42969
EMC ECS - update to 3.7.0.6
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
IBM Spectrum Protect Plus - update to 10.1.17.1
ObjectScale - update to 1.4.0
python3-py - addressed in versions 1.8.1-11.15.2, 1.8.1-11.18.1, 1.10.0-150100.5.12.1
python-py - addressed in versions 1.8.1-11.15.2, 1.8.1-11.18.1
watsonx.data - update to 2.0.3
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
EMC ViPR SRM - update to 4.9.0.0
IBM Netezza for Cloud Pak for Data - update to 11.2.3.3
External References
Related Security Bulletins
- Denial of service in python-py
- SUSE update for python-py
- SUSE update for python-py
- SUSE update for python-py
- Incorrect regular expression in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in Dell ObjectScale
- Incorrect regular expression in IBM watsonx.data
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in IBM Netezza for Cloud Pak for Data (on Cloud)
- Multiple vulnerabilities in IBM Spectrum Protect Plus