DEBIAN-CVE-2022-40897

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2022-40897
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-40897.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2022-40897
Upstream
Published
2022-12-23T00:15:13Z
Modified
2025-09-18T02:48:41.260881Z
Summary
[none]
Details

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

References

Affected packages

Debian:11 / setuptools

Package

Name
setuptools
Purl
pkg:deb/debian/setuptools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
52.0.0-4+deb11u1

Affected versions

52.*

52.0.0-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / setuptools

Package

Name
setuptools
Purl
pkg:deb/debian/setuptools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
65.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / setuptools

Package

Name
setuptools
Purl
pkg:deb/debian/setuptools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
65.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / setuptools

Package

Name
setuptools
Purl
pkg:deb/debian/setuptools?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
65.6.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}