ISOMAN

CVE

CVE-2020-8492

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

Severity
MEDIUM
CVSS
6.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
  2. https://bugs.python.org/issue39503
  3. https://github.com/python/cpython/pull/18284
  4. https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E
  5. https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E
  6. https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html
  7. https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
  8. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/
  9. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/
  10. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/
  11. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/
  12. https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html
  13. https://security.gentoo.org/glsa/202005-09
  14. https://security.netapp.com/advisory/ntap-20200221-0001/
  15. https://usn.ubuntu.com/4333-1/
  16. https://usn.ubuntu.com/4333-2/
  17. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html
  18. https://bugs.python.org/issue39503
  19. https://github.com/python/cpython/pull/18284
  20. https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E