Bugzilla – Bug 1215804
VUL-0: CVE-2021-29063: python-mpmath: regular expression denial of service in the mpmathify function
Last modified: 2024-04-16 08:02:55 UTC
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-29063
Upstream fix: https://github.com/mpmath/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750
https://github.com/mpmath/mpmath/issues/654 "Looks like mpmath v1.0.0 through v1.2.1 is affected by CVE-2021-29063: Regular Expression Denial of Service (ReDOS) vulnerability when the mpmathify function is called." We need submissions for: openSUSE:Backports:SLE-15-SP4 python-mpmath openSUSE:Backports:SLE-15-SP5 python-mpmath openSUSE:Backports:SLE-15-SP6 python-mpmath SP6 can still be submitted to the GA project.
I'm the wrong person for this package.
This is an autogenerated message for OBS integration: This bug (1215804) was mentioned in https://build.opensuse.org/request/show/1114257 Factory / python-mpmath
I'm not the maintainer.