Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 879813 (CVE-2022-40897)

Summary: <dev-python/setuptools-65.5.1: REDoS vector in package_index
Product: Gentoo Security Reporter: Michał Górny <mgorny>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: python
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/pypa/setuptools/issues/3659
Whiteboard: A3 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on: 879811    
Bug Blocks:    

Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 04:36:16 UTC
+* #3659: Fixed REDoS vector in package_index.

> As described through PSRT channel, it may end in a DoS if an user is fetching malicious HTML from a package in PyPI or custom PackageIndex page.

https://github.com/pypa/setuptools/issues/3659
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 11:01:24 UTC
cleanup done.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-05 13:17:50 UTC
Thanks!
Comment 3 Larry the Git Cow gentoo-dev 2024-05-05 06:38:35 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=49959bcac23a9f3214baf5919f43e5744cb0a6d5

commit 49959bcac23a9f3214baf5919f43e5744cb0a6d5
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2024-05-05 06:37:49 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2024-05-05 06:38:17 +0000

    [ GLSA 202405-10 ] Setuptools: Denial of Service
    
    Bug: https://bugs.gentoo.org/879813
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202405-10.xml | 42 ++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 42 insertions(+)