QID 981980
QID 981980: Python (pip) Security Update for aioxmpp (GHSA-6m9g-jr8c-cqw3)
Security update has been released for aioxmpp to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Possible remote Denial of Service or Data Injection.
Solution
Patches are available in https://github.com/horazont/aioxmpp/pull/268. They have been backported to the 0.10 release series and 0.10.3 is the first release to contain the fix.Workaround:
To make the bug exploitable, an error suppressing ``xso_error_handler`` is required. By not using ``xso_error_handlers`` or not using the suppression function, the vulnerability can be mitigated completely (to our knowledge).
To make the bug exploitable, an error suppressing ``xso_error_handler`` is required. By not using ``xso_error_handlers`` or not using the suppression function, the vulnerability can be mitigated completely (to our knowledge).
Vendor References
- GHSA-6m9g-jr8c-cqw3 -
github.com/advisories/GHSA-6m9g-jr8c-cqw3
CVEs related to QID 981980
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6m9g-jr8c-cqw3 | aioxmpp |
|