Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: Python-Py Moderate ReDoS Attack Fix MGASA-2025-0289

mageia
Calendar Grey November 14, 2025
Dist Mageia Esm H88
Updated python-py packages fix a ReDoS attack vulnerability in Mageia 9, impacting security and performance.
MGASA-2025-0289 - Updated python-py packages fix security vulnerability

Summary

Description: The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. (CVE-2022-42969)

References

- https://bugs.mageia.org/show_bug.cgi?id=31458

- https://lists.suse.com/pipermail/sle-security-updates/2023-January/013536.html

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ELXQR2N4BOTGP4YQAZGZJDQMETKR6DWY/

- https://www.cve.org/CVERecord?id=CVE-2022-42969

Resolution

SRPMS

- 9/core/python-py-1.11.0-2.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 13 Nov 2025
URL: https://advisories.mageia.org/MGASA-2025-0289.html
Type: security
CVE: CVE-2022-42969

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here