Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia: 2021-0149 Moderate: Python-cairosvg Denial of Service Attack

mageia
Calendar Grey March 21, 2021
Dist Mageia Esm H88
Newly revised python-cairosvg packages mitigate Regular Expression Denial of Service threats on Mageia platforms.
When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS)

Summary

When processing SVG files, the python package CairoSVG uses two regular expressions which are vulnerable to Regular Expression Denial of Service (REDoS). If an attacker provides a malicious SVG, it can make cairosvg get stuck processing the file for a very long time (CVE-2021-21236).

References

- https://bugs.mageia.org/show_bug.cgi?id=28122

- https://github.com/advisories/GHSA-hq37-853p-g5cf

- https://www.cve.org/CVERecord?id=CVE-2021-21236

Resolution

SRPMS

- 7/core/python-cairosvg-2.2.1-1.1.mga7

Publication date: 21 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0149.html
Type: security
CVE: CVE-2021-21236

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here