Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-40897
HistoryDec 23, 2022 - 12:00 a.m.

CVE-2022-40897

2022-12-2300:00:00
ubuntu.com
ubuntu.com
230
pypa setuptools
vulnerability
package_index.py
denial of service
remote attackers
html
crafted package
custom packageindex page

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

77.5%

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote
attackers to cause a denial of service via HTML in a crafted package or
custom PackageIndex page. There is a Regular Expression Denial of Service
(ReDoS) in package_index.py.

Notes

Author Note
mdeslaur the python-pip package bundles python-setuptools binaries when built. After updating python-setuptools, a no-change rebuild of python-pip is required.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpython-pip< 9.0.1-2.3~ubuntu1.18.04.6UNKNOWN
ubuntu20.04noarchpython-pip< 20.0.2-5ubuntu1.7UNKNOWN
ubuntu22.04noarchpython-pip< 22.0.2+dfsg-1ubuntu0.1UNKNOWN
ubuntu22.10noarchpython-pip< 22.2+dfsg-1ubuntu0.1UNKNOWN
ubuntu14.04noarchpython-pip< 1.5.4-1ubuntu4+esm2UNKNOWN
ubuntu16.04noarchpython-pip< 8.1.1-2ubuntu0.6+esm3UNKNOWN
ubuntu18.04noarchpython-setuptools< 39.0.1-2ubuntu0.1UNKNOWN
ubuntu20.04noarchpython-setuptools< 44.0.0-2ubuntu0.1UNKNOWN
ubuntu22.04noarchpython-setuptools< 44.1.1-1.2ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchpython-setuptools< 44.1.1-1.2ubuntu0.22.10.1UNKNOWN
Rows per page:
1-10 of 151

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

0.005 Low

EPSS

Percentile

77.5%