Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
{
"binaries": [
{
"binary_version": "9.0.1-2.3~ubuntu1.18.04.6",
"binary_name": "python-pip"
},
{
"binary_version": "9.0.1-2.3~ubuntu1.18.04.6",
"binary_name": "python-pip-whl"
},
{
"binary_version": "9.0.1-2.3~ubuntu1.18.04.6",
"binary_name": "python3-pip"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "pypy-pkg-resources"
},
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "pypy-setuptools"
},
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "python-pkg-resources"
},
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "python-setuptools"
},
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "python3-pkg-resources"
},
{
"binary_version": "39.0.1-2ubuntu0.1",
"binary_name": "python3-setuptools"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "44.0.0-2ubuntu0.1",
"binary_name": "pypy-pkg-resources"
},
{
"binary_version": "44.0.0-2ubuntu0.1",
"binary_name": "pypy-setuptools"
},
{
"binary_version": "44.0.0-2ubuntu0.1",
"binary_name": "python-pkg-resources"
},
{
"binary_version": "44.0.0-2ubuntu0.1",
"binary_name": "python-setuptools"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "44.1.1-1.2ubuntu0.22.04.1",
"binary_name": "pypy-pkg-resources"
},
{
"binary_version": "44.1.1-1.2ubuntu0.22.04.1",
"binary_name": "pypy-setuptools"
},
{
"binary_version": "44.1.1-1.2ubuntu0.22.04.1",
"binary_name": "python-pkg-resources"
},
{
"binary_version": "44.1.1-1.2ubuntu0.22.04.1",
"binary_name": "python-setuptools"
},
{
"binary_version": "44.1.1-1.2ubuntu0.22.04.1",
"binary_name": "python2-setuptools-whl"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "59.6.0-1.2ubuntu0.22.04.1",
"binary_name": "python3-pkg-resources"
},
{
"binary_version": "59.6.0-1.2ubuntu0.22.04.1",
"binary_name": "python3-setuptools"
},
{
"binary_version": "59.6.0-1.2ubuntu0.22.04.1",
"binary_name": "python3-setuptools-whl"
}
],
"availability": "No subscription required"
}{
"binaries": [
{
"binary_version": "1.5.4-1ubuntu4+esm2",
"binary_name": "python-pip"
},
{
"binary_version": "1.5.4-1ubuntu4+esm2",
"binary_name": "python-pip-whl"
},
{
"binary_version": "1.5.4-1ubuntu4+esm2",
"binary_name": "python3-pip"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "3.3-1ubuntu2+esm1",
"binary_name": "python-pkg-resources"
},
{
"binary_version": "3.3-1ubuntu2+esm1",
"binary_name": "python-setuptools"
},
{
"binary_version": "3.3-1ubuntu2+esm1",
"binary_name": "python-setuptools-whl"
},
{
"binary_version": "3.3-1ubuntu2+esm1",
"binary_name": "python3-pkg-resources"
},
{
"binary_version": "3.3-1ubuntu2+esm1",
"binary_name": "python3-setuptools"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "pypy-pkg-resources"
},
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "pypy-setuptools"
},
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "python-pkg-resources"
},
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "python-setuptools"
},
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "python3-pkg-resources"
},
{
"binary_version": "20.7.0-1ubuntu0.1~esm1",
"binary_name": "python3-setuptools"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}{
"binaries": [
{
"binary_version": "8.1.1-2ubuntu0.6+esm3",
"binary_name": "python-pip"
},
{
"binary_version": "8.1.1-2ubuntu0.6+esm3",
"binary_name": "python-pip-whl"
},
{
"binary_version": "8.1.1-2ubuntu0.6+esm3",
"binary_name": "python3-pip"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}