|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-4068: python-panel: the npm package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Distribution | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Security | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED INVALID | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | daniel.garcia, gabriele.sonnu |
| Version: | Leap 15.6 | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/405385/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-4068:7.5:(AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1224256 | ||
|
Description
SMASH SMASH
2024-05-16 12:02:38 UTC
A vulnerable version (3.0.2) of the braces package is embedded in: - openSUSE:Factory/python-panel Upstream issue: https://github.com/micromatch/braces/issues/35 Same issue https://bugzilla.suse.com/show_bug.cgi?id=1224381, different CVE number. Looks like there's a fix in braces upstream [1] to avoid this issue. There will be a new release soon. [1] https://github.com/micromatch/braces/pull/37 From https://bugzilla.suse.com/show_bug.cgi?id=1224381#c2 > This code is not part of this python package, it's a devel node module used upstream for developers, so we can certainly say that it's not affected by this bug. Closing this. |