Code Injection in ReportLab - CVE-2023-33733
Published: June 22, 2023 / Updated: August 16, 2024
Vulnerability identifier: #VU77651
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33733
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation when handling PDF files. A remote attacker can pass a specially crafted PDF file to the application and execute arbitrary code on the target system.
Affected software
ReportLab
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Workstation Extension 12
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Fedora
Splunk Enterprise
python-reportlab
python-reportlab-debugsource
python-reportlab-debuginfo
python3-reportlab-debuginfo
python3-reportlab
python3-reportlab (Ubuntu package)
python-reportlab-help
python-reportlab (Debian package)
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Workstation Extension 12
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Fedora
Splunk Enterprise
python-reportlab
python-reportlab-debugsource
python-reportlab-debuginfo
python3-reportlab-debuginfo
python3-reportlab
python3-reportlab (Ubuntu package)
python-reportlab-help
python-reportlab (Debian package)
How to mitigate CVE-2023-33733
Install updates from vendor's website.
ReportLab - update to 3.6.13
Splunk Enterprise - addressed in versions 9.0.10, 9.1.5, 9.2.2
python-reportlab - update to 2.7-3.13.1
python-reportlab-debugsource - addressed in versions 2.7-3.13.1, 3.4.0-150000.3.9.1
python-reportlab-debuginfo - addressed in versions 2.7-3.13.1, 3.4.0-150000.3.9.1
python3-reportlab-debuginfo - update to 3.4.0-150000.3.9.1
python3-reportlab - update to 3.4.0-150000.3.9.1
python3-reportlab (Ubuntu package) - addressed in versions 3.5.34-1ubuntu1.1, 3.6.8-1ubuntu0.1, 3.6.11-1ubuntu0.1, 3.6.12-1ubuntu0.1
python-reportlab-debugsource - update to 3.6.10-2
python3-reportlab - update to 3.6.10-2
python-reportlab-debuginfo - update to 3.6.10-2
python-reportlab - update to 3.6.10-2
python-reportlab-help - update to 3.6.10-2
python-reportlab (Debian package) - update to 3.6.12-1+deb12u1
python-reportlab - addressed in versions 4.0.4-2.fc37, 4.0.4-2.fc38
Splunk Enterprise - addressed in versions 9.0.10, 9.1.5, 9.2.2
python-reportlab - update to 2.7-3.13.1
python-reportlab-debugsource - addressed in versions 2.7-3.13.1, 3.4.0-150000.3.9.1
python-reportlab-debuginfo - addressed in versions 2.7-3.13.1, 3.4.0-150000.3.9.1
python3-reportlab-debuginfo - update to 3.4.0-150000.3.9.1
python3-reportlab - update to 3.4.0-150000.3.9.1
python3-reportlab (Ubuntu package) - addressed in versions 3.5.34-1ubuntu1.1, 3.6.8-1ubuntu0.1, 3.6.11-1ubuntu0.1, 3.6.12-1ubuntu0.1
python-reportlab-debugsource - update to 3.6.10-2
python3-reportlab - update to 3.6.10-2
python-reportlab-debuginfo - update to 3.6.10-2
python-reportlab - update to 3.6.10-2
python-reportlab-help - update to 3.6.10-2
python-reportlab (Debian package) - update to 3.6.12-1+deb12u1
python-reportlab - addressed in versions 4.0.4-2.fc37, 4.0.4-2.fc38
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Reportlab
- SUSE update for python-reportlab
- SUSE update for python-reportlab
- Ubuntu update for python-reportlab
- Fedora 38 update for python-reportlab
- Fedora 37 update for python-reportlab
- openEuler update for python-reportlab
- Splunk Enterprise update for ReportLab
- Debian update for python-reportlab