Incorrect Regular Expression in HTML::StripScripts - CVE-2023-24038
Published: February 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input in _hss_attval_style. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
Debian Linux
Fedora
Ubuntu
libhtml-stripscripts-perl (Ubuntu package)
libhtml-stripscripts-perl (Debian package)
perl-HTML-StripScripts
How to mitigate CVE-2023-24038
libhtml-stripscripts-perl (Debian package) - update to 1.06-1+deb11u1
perl-HTML-StripScripts - addressed in versions 1.06-22.el7, 1.06-22.el8, 1.06-22.el9, 1.06-22.fc37, 1.06-22.fc38
External References
Related Security Bulletins
- Denial of service in HTML-StripScripts
- Debian update for libhtml-stripscripts-perl
- Ubuntu update for libhtml-stripscripts-perl
- Fedora EPEL 9 update for perl-HTML-StripScripts
- Fedora EPEL 8 update for perl-HTML-StripScripts
- Fedora EPEL 7 update for perl-HTML-StripScripts
- Fedora 38 update for perl-HTML-StripScripts
- Fedora 37 update for perl-HTML-StripScripts