UBUNTU-CVE-2021-3733
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3733
UBUNTU-CVE-2021-3733
Summary:
Details: There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
References: https://ubuntu.com/security/CVE-2021-3733, https://bugs.python.org/issue43075, https://github.com/python/cpython/pull/24391, https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb1defe1, https://github.com/python/cpython/commit/a21d4fbd549ec9685068a113660553d7f80d9b09, https://github.com/python/cpython/commit/e7654b6046090914a8323931ed759a94a5f85d60, https://github.com/python/cpython/commit/ada14995870abddc277addf57dd690a2af04c2da, https://github.com/python/cpython/commit/3fbe96123aeb66664fa547a8f6022efa2dc8788f, https://ubuntu.com/security/notices/USN-5083-1, https://ubuntu.com/security/notices/USN-5199-1, https://ubuntu.com/security/notices/USN-5200-1, https://www.cve.org/CVERecord?id=CVE-2021-3733, https://ubuntu.com/security/notices/USN-6891-1
Affected packages
Package
Name: python3.4
Purl: pkg:deb/ubuntu/[email protected]~14.04.7+esm11?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
