UBUNTU-CVE-2020-8492
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-8492
UBUNTU-CVE-2020-8492
Summary:
Details: Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
References: https://ubuntu.com/security/CVE-2020-8492, https://github.com/python/cpython/pull/18284, https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html, https://github.com/python/cpython/commit/0b297d4ff1c0e4480ad33acae793fbaf4bf015b4, https://ubuntu.com/security/notices/USN-4333-1, https://ubuntu.com/security/notices/USN-4333-2, https://ubuntu.com/security/notices/USN-4754-3, https://ubuntu.com/security/notices/USN-5200-1, https://www.cve.org/CVERecord?id=CVE-2020-8492, https://ubuntu.com/security/notices/USN-6891-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
