GHSA-6m9g-jr8c-cqw3

    Dashboard / Vulnerabilities / GHSA-6m9g-jr8c-cqw3

    GHSA-6m9g-jr8c-cqw3

    Published: 29 Apr 2020Last Modified: 4 Sept 2024

    Summary: Depth counting error in guard() leading to multiple potential security issues in aioxmpp

    Details: ### Impact Possible remote Denial of Service or Data Injection. ### Patches Patches are available in https://github.com/horazont/aioxmpp/pull/268. They have been backported to the 0.10 release series and 0.10.3 is the first release to contain the fix. ### Workarounds To make the bug exploitable, an error suppressing ``xso_error_handler`` is required. By not using ``xso_error_handlers`` or not using the suppression function, the vulnerability can be mitigated completely (to our knowledge). ### References The pull request contains a detailed description: https://github.com/horazont/aioxmpp/pull/268 ### For more information If you have any questions or comments about this advisory: * [Join our chat](xmpp:[email protected]?join) * Email the maintainer [Jonas Schäfer](mailto:[email protected])

    Affected packages

    Package

    Name: aioxmpp

    Purl: pkg:pypi/aioxmpp

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.10.3

    Affected versions

    0.10.0
    0.10.1
    0.10.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High