[Bug 1231408] New: VUL-0: CVE-2024-25885: python-xhtml2pdf: regular expression denial of service through the getcolor function in utils.py
https://bugzilla.suse.com/show_bug.cgi?id=1231408 Bug ID: 1231408 Summary: VUL-0: CVE-2024-25885: python-xhtml2pdf: regular expression denial of service through the getcolor function in utils.py Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/423265/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: python-maintainers@suse.com Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: camila.matos@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-25885 https://www.cve.org/CVERecord?id=CVE-2024-25885 http://dirk.com http://xhtml2pdf.com https://gist.github.com/salvatore-abello/c88dd0027496774023ef36c7b576d206 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 https://bugzilla.suse.com/show_bug.cgi?id=1231408#c1 --- Comment #1 from Camila Camargo de Matos <camila.matos@suse.com> --- It seems like package python-xhtml2pdf would require a fix in the below codestreams: - openSUSE:Backports:SLE-15-SP5 - openSUSE:Backports:SLE-15-SP6 - openSUSE:Factory -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 SMASH SMASH <smash_bz@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 Steve Kowalik <steven.kowalik@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |steven.kowalik@suse.com -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 https://bugzilla.suse.com/show_bug.cgi?id=1231408#c3 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |mmachova@suse.com --- Comment #3 from Markéta Machová <mmachova@suse.com> --- Just to be clear: is it an issue in the `getColor` function in `xhtml2pdf/util.py`? -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 https://bugzilla.suse.com/show_bug.cgi?id=1231408#c4 --- Comment #4 from Camila Camargo de Matos <camila.matos@suse.com> --- (In reply to Markéta Machová from comment #3)
Just to be clear: is it an issue in the `getColor` function in `xhtml2pdf/util.py`?
According to the reporter [0], it seems like that is the case. [0] https://gist.github.com/salvatore-abello/c88dd0027496774023ef36c7b576d206 -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 Camila Camargo de Matos <camila.matos@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|VUL-0: CVE-2024-25885: |VUL-0: CVE-2024-25885: |python-xhtml2pdf: regular |python-xhtml2pdf: regular |expression denial of |expression denial of |service through the |service through the |getcolor function in |getColor() function in |utils.py |utils.py -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 https://bugzilla.suse.com/show_bug.cgi?id=1231408#c5 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|python-maintainers@suse.com |mmachova@suse.com --- Comment #5 from Markéta Machová <mmachova@suse.com> --- Thanks. I will try to resolve it. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1231408 https://bugzilla.suse.com/show_bug.cgi?id=1231408#c6 Markéta Machová <mmachova@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|mmachova@suse.com |security-team@suse.de Status|NEW |IN_PROGRESS --- Comment #6 from Markéta Machová <mmachova@suse.com> --- I finally got to this bug, found out there is already a patch upstream and sent SRs. Will be fixed soon in all affected codestreams. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com