Resource exhaustion in Python - CVE-2022-48564

 

Resource exhaustion in Python - CVE-2022-48564

Published: October 17, 2023


Vulnerability identifier: #VU82077
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-48564
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability occurs when processing malformed Apple Property List files in binary format. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Python
Service Telemetry Framework
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat Advanced Cluster Security for Kubernetes
IBM Workload Scheduler
Dell EMC PowerProtect Data Protection
SmartFabric OS10
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Watson CP4D Data Stores
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3.6 (Ubuntu package)
python3.11 (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.8 (Ubuntu package)
python3.8-minimal (Ubuntu package)
python3.9 (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.5-minimal (Ubuntu package)
python2.7 (Ubuntu package)
python3 (Red Hat package)
platform-python
python3-libs
python3-test
python3-tkinter
python3-idle
python3-devel
platform-python-devel
platform-python-debug
python3.10 (Ubuntu package)
python3.10-minimal (Ubuntu package)
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
Red Hat OpenShift GitOps

How to mitigate CVE-2022-48564

Install updates from vendor's website.

Python - update to 3.9.2
Service Telemetry Framework - update to 1.5.4
IBM Process Mining - update to 1.14.2
Dell EMC PowerProtect Data Protection - update to 2.7.8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.1.6
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
SmartFabric OS10 - addressed in versions 10.5.4.11, 10.5.6.1
python3.6 (Ubuntu package) - update to Ubuntu Pro
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.4-1~23.04.1, 3.11.6-3ubuntu0.1
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.9, 3.8.10-0ubuntu1~20.04.10
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.10
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.6-minimal (Ubuntu package) - update to Ubuntu Pro
python3.7 (Ubuntu package) - update to Ubuntu Pro
python3.7-minimal (Ubuntu package) - update to Ubuntu Pro
python3.5 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
python3.5-minimal (Ubuntu package) - update to Ubuntu Pro
python2.7 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.11
python3 (Red Hat package) - addressed in versions 3.6.8-47.el8_6.4, 3.6.8-51.el8_8.4
platform-python - update to 3.6.8-56.0.1
python3-libs - update to 3.6.8-56.0.1
python3-test - update to 3.6.8-56.0.1
python3-tkinter - update to 3.6.8-56.0.1
python3-idle - update to 3.6.8-56.0.1
python3-devel - update to 3.6.8-56.0.1
platform-python-devel - update to 3.6.8-56.0.1
platform-python-debug - update to 3.6.8-56.0.1
python3.10 (Ubuntu package) - addressed in versions 3.10.12-1~22.04.3, 3.10.12-1~22.04.4
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
Enterprise SONiC - update to 4.2.1
IBM Cloud Pak for Watson AIOps - update to 4.5.0
Watson CP4D Data Stores - update to 5.0.3
IBM Workload Scheduler - addressed in versions 10.1.0.5, 10.2.3

External References

Related Security Bulletins