Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 861353 (CVE-2022-31471, CVE-2022-33977) - <dev-python/untangle-1.2.1: multiple vulnerabilities
Summary: <dev-python/untangle-1.2.1: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2022-31471, CVE-2022-33977
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/stchris/untangle/r...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 861416
Blocks:
  Show dependency tree
 
Reported: 2022-07-27 06:00 UTC by John Helmert III
Modified: 2022-07-27 15:14 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-07-27 06:00:54 UTC
CVE-2022-31471 (https://jvn.jp/en/jp/JVN30454777/):

untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.

CVE-2022-33977 (https://jvn.jp/en/jp/JVN30454777/):

untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.

Please report security bugs when security issues are in changelogs!

Please stable when ready.
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-07-27 09:05:08 UTC
cleanup done
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-07-27 15:14:55 UTC
Thanks, all done!