CVE-2021-32837
Summary
| CVE | CVE-2021-32837 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-17 22:15:00 UTC |
| Updated | 2023-06-20 17:15:00 UTC |
| Description | mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3460-1] python-mechanize security update |
MLIST |
lists.debian.org |
|
| GHSL-2021-108: ReDoS (Regular Expression Denial of Service) in mechanize - CVE-2021-32837 | GitHub Security Lab |
CONFIRM |
securitylab.github.com |
|
| Release v0.4.6 · python-mechanize/mechanize · GitHub |
MISC |
github.com |
|
| mechanize/_urllib2_fork.py at 3acb1836f3fd8edc5a758a417dd46b53832ae3b5 · python-mechanize/mechanize · GitHub |
MISC |
github.com |
|
| Use the current upstream (python3.9) authreq header parsing regex · python-mechanize/mechanize@dd05334 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182113 Debian Security Update for python-mechanize (CVE-2021-32837)
- 6000109 Debian Security Update for python-mechanize (DLA 3460-1)