Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 879813 - <dev-python/setuptools-65.5.1: REDoS vector in package_index
Summary: <dev-python/setuptools-65.5.1: REDoS vector in package_index
Status: IN_PROGRESS
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://github.com/pypa/setuptools/is...
Whiteboard: A3 [glsa]
Keywords:
Depends on: 879811
Blocks:
  Show dependency tree
 
Reported: 2022-11-05 04:36 UTC by Michał Górny
Modified: 2024-04-06 09:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 04:36:16 UTC
+* #3659: Fixed REDoS vector in package_index.

> As described through PSRT channel, it may end in a DoS if an user is fetching malicious HTML from a package in PyPI or custom PackageIndex page.

https://github.com/pypa/setuptools/issues/3659
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 11:01:24 UTC
cleanup done.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 13:17:50 UTC
Thanks!