rpm package
suse/python-py&distro=SUSE Linux Enterprise Micro 5.2
pkg:rpm/suse/python-py&distro=SUSE%20Linux%20Enterprise%20Micro%205.2
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-42969 | — | < 1.10.0-150100.5.12.1 | 1.10.0-150100.5.12.1 | Oct 16, 2022 | The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third | ||
| CVE-2020-29651 | — | < 1.10.0-150000.5.9.2 | 1.10.0-150000.5.9.2 | Dec 9, 2020 | A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
- CVE-2022-42969Oct 16, 2022affected < 1.10.0-150100.5.12.1fixed 1.10.0-150100.5.12.1
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third
- CVE-2020-29651Dec 9, 2020affected < 1.10.0-150000.5.9.2fixed 1.10.0-150000.5.9.2
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.