Inefficient regular expression complexity in configobj - CVE-2023-26112
Published: August 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Basesystem Module
openSUSE Leap
Anolis OS
Fedora
IBM Watson Assistant for IBM Cloud Pak for Data
python3-configobj (Ubuntu package)
python-configobj (Ubuntu package)
python3-configobj
python-configobj
python2-configobj
python3-configobj-doc
How to mitigate CVE-2023-26112
python3-configobj (Ubuntu package) - addressed in versions Ubuntu Pro, 5.0.6-4ubuntu0.1, 5.0.6-5ubuntu0.1
python-configobj (Ubuntu package) - update to Ubuntu Pro
python3-configobj - addressed in versions 5.0.6-20.8.1, 5.0.6-150000.3.3.1
python-configobj - update to 5.0.6-20.8.1
python-configobj - update to 5.0.6-23
python2-configobj - update to 5.0.6-150000.3.3.1
python3-configobj - update to 5.0.8-2
python3-configobj-doc - update to 5.0.8-2
python-configobj - addressed in versions 5.0.8-6.fc37, 5.0.8-6.fc38, 5.0.8-6.fc39
External References
Related Security Bulletins
- Denial of service in configobj
- SUSE update for python-configobj
- SUSE update for python-configobj
- Inefficient regular expression complexity in IBM Watson Assistant for IBM Cloud Pak for Data
- Fedora 38 update for python-configobj
- Fedora 39 update for python-configobj
- Fedora 37 update for python-configobj
- Ubuntu update for configobj
- Ubuntu update for configobj
- Amazon Linux AMI update for python-configobj
- Anolis OS update for python-configobj