CVE-2021-44686
Summary
| CVE | CVE-2021-44686 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-07 00:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: calibre-4.23.0-8.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Comparing v5.31.1...v5.32.0 · kovidgoyal/calibre · GitHub |
MISC |
github.com |
|
| Bug #1951979 “calibre contains a regular expression that is vuln...” : Bugs : calibre |
MISC |
bugs.launchpad.net |
|
| ReDoS in calibre · Issue #18 · dwisiswant0/advisory · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: calibre-4.23.0-8.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 182907 Debian Security Update for calibre (CVE-2021-44686)
- 282180 Fedora Security Update for calibre (FEDORA-2021-e42fadbcc3)