rpm package
suse/python-py&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5
pkg:rpm/suse/python-py&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-42969 | — | < 1.8.1-11.15.2 | 1.8.1-11.15.2 | Oct 16, 2022 | The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third | ||
| CVE-2020-29651 | — | < 1.8.1-11.12.4 | 1.8.1-11.12.4 | Dec 9, 2020 | A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality. |
- CVE-2022-42969Oct 16, 2022affected < 1.8.1-11.15.2fixed 1.8.1-11.15.2
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third
- CVE-2020-29651Dec 9, 2020affected < 1.8.1-11.12.4fixed 1.8.1-11.12.4
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.