UBUNTU-CVE-2022-40897

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2022-40897
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-40897.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-40897
Related
Published
2022-12-23T00:15:00Z
Modified
2022-12-23T00:15:00Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

References

Affected packages

Ubuntu:Pro:14.04:LTS / python-pip

Package

Name
python-pip
Purl
pkg:deb/ubuntu/python-pip@1.5.4-1ubuntu4+esm2?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.5.4-1ubuntu4+esm2

Affected versions

1.*

1.4.1-2
1.5.4-1
1.5.4-1ubuntu1
1.5.4-1ubuntu3
1.5.4-1ubuntu4
1.5.4-1ubuntu4+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-pip": "1.5.4-1ubuntu4+esm2",
            "python-pip-whl": "1.5.4-1ubuntu4+esm2",
            "python3-pip": "1.5.4-1ubuntu4+esm2"
        }
    ]
}

Ubuntu:Pro:14.04:LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:deb/ubuntu/python-setuptools@3.3-1ubuntu2+esm1?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3-1ubuntu2+esm1

Affected versions

1.*

1.4.2-1

2.*

2.0.1-1ubuntu1
2.0.1-2ubuntu1
2.0.2-1
2.1-1
2.2-1

3.*

3.3-1ubuntu1
3.3-1ubuntu2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-setuptools-doc": "3.3-1ubuntu2+esm1",
            "python-setuptools-whl": "3.3-1ubuntu2+esm1",
            "python-pkg-resources": "3.3-1ubuntu2+esm1",
            "python-setuptools": "3.3-1ubuntu2+esm1",
            "python3-pkg-resources": "3.3-1ubuntu2+esm1",
            "python3-setuptools": "3.3-1ubuntu2+esm1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:deb/ubuntu/python-setuptools@20.7.0-1ubuntu0.1~esm1?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.7.0-1ubuntu0.1~esm1

Affected versions

18.*

18.4-1
18.4-2
18.7-1
18.8-1

20.*

20.1.1-1
20.3.1-1
20.7.0-1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-setuptools": "20.7.0-1ubuntu0.1~esm1",
            "python-setuptools": "20.7.0-1ubuntu0.1~esm1",
            "python-pkg-resources": "20.7.0-1ubuntu0.1~esm1",
            "pypy-setuptools": "20.7.0-1ubuntu0.1~esm1",
            "pypy-pkg-resources": "20.7.0-1ubuntu0.1~esm1",
            "python3-pkg-resources": "20.7.0-1ubuntu0.1~esm1",
            "python-setuptools-doc": "20.7.0-1ubuntu0.1~esm1"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / python-pip

Package

Name
python-pip
Purl
pkg:deb/ubuntu/python-pip@8.1.1-2ubuntu0.6+esm3?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.1.1-2ubuntu0.6+esm3

Affected versions

1.*

1.5.6-7ubuntu1
1.5.6-7ubuntu2

8.*

8.0.2-7
8.0.3-1
8.0.3-2
8.1.0-1
8.1.0-2
8.1.1-1
8.1.1-2
8.1.1-2ubuntu0.1
8.1.1-2ubuntu0.2
8.1.1-2ubuntu0.4
8.1.1-2ubuntu0.6
8.1.1-2ubuntu0.6+esm2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-pip": "8.1.1-2ubuntu0.6+esm3",
            "python-pip-whl": "8.1.1-2ubuntu0.6+esm3",
            "python3-pip": "8.1.1-2ubuntu0.6+esm3"
        }
    ]
}

Ubuntu:18.04:LTS / python-pip

Package

Name
python-pip
Purl
pkg:deb/ubuntu/python-pip@9.0.1-2.3~ubuntu1.18.04.6?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.1-2.3~ubuntu1.18.04.6

Affected versions

9.*

9.0.1-2
9.0.1-2.3~ubuntu1
9.0.1-2.3~ubuntu1.18.04.1
9.0.1-2.3~ubuntu1.18.04.2
9.0.1-2.3~ubuntu1.18.04.3
9.0.1-2.3~ubuntu1.18.04.4
9.0.1-2.3~ubuntu1.18.04.5

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-pip": "9.0.1-2.3~ubuntu1.18.04.6",
            "python-pip-whl": "9.0.1-2.3~ubuntu1.18.04.6",
            "python3-pip": "9.0.1-2.3~ubuntu1.18.04.6"
        }
    ]
}

Ubuntu:18.04:LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:deb/ubuntu/python-setuptools@39.0.1-2ubuntu0.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
39.0.1-2ubuntu0.1

Affected versions

36.*

36.2.7-2

38.*

38.4.0-1
38.5.2-1

39.*

39.0.1-1
39.0.1-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-setuptools": "39.0.1-2ubuntu0.1",
            "python-setuptools": "39.0.1-2ubuntu0.1",
            "python-pkg-resources": "39.0.1-2ubuntu0.1",
            "pypy-setuptools": "39.0.1-2ubuntu0.1",
            "pypy-pkg-resources": "39.0.1-2ubuntu0.1",
            "python3-pkg-resources": "39.0.1-2ubuntu0.1",
            "python-setuptools-doc": "39.0.1-2ubuntu0.1"
        }
    ]
}

Ubuntu:20.04:LTS / python-pip

Package

Name
python-pip
Purl
pkg:deb/ubuntu/python-pip@20.0.2-5ubuntu1.7?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.0.2-5ubuntu1.7

Affected versions

18.*

18.1-5
18.1-5build1
18.1-5ubuntu1

20.*

20.0.2-2
20.0.2-4
20.0.2-5
20.0.2-5ubuntu1
20.0.2-5ubuntu1.1
20.0.2-5ubuntu1.3
20.0.2-5ubuntu1.4
20.0.2-5ubuntu1.5
20.0.2-5ubuntu1.6

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python-pip-whl": "20.0.2-5ubuntu1.7",
            "python3-pip": "20.0.2-5ubuntu1.7"
        }
    ]
}

Ubuntu:20.04:LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:deb/ubuntu/python-setuptools@44.0.0-2ubuntu0.1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
44.0.0-2ubuntu0.1

Affected versions

41.*

41.1.0-1
41.4.0-1

44.*

44.0.0-1
44.0.0-2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "pypy-setuptools": "44.0.0-2ubuntu0.1",
            "pypy-pkg-resources": "44.0.0-2ubuntu0.1",
            "python-setuptools": "44.0.0-2ubuntu0.1",
            "python-pkg-resources": "44.0.0-2ubuntu0.1"
        }
    ]
}

Ubuntu:20.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools@45.2.0-1ubuntu0.1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
45.2.0-1ubuntu0.1

Affected versions

45.*

45.2.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-setuptools": "45.2.0-1ubuntu0.1",
            "python-setuptools-doc": "45.2.0-1ubuntu0.1",
            "python3-pkg-resources": "45.2.0-1ubuntu0.1"
        }
    ]
}

Ubuntu:22.04:LTS / python-pip

Package

Name
python-pip
Purl
pkg:deb/ubuntu/python-pip@22.0.2+dfsg-1ubuntu0.1?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.0.2+dfsg-1ubuntu0.1

Affected versions

20.*

20.3.4-4

21.*

21.3.1+dfsg-3

22.*

22.0.2+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-pip-whl": "22.0.2+dfsg-1ubuntu0.1",
            "python3-pip": "22.0.2+dfsg-1ubuntu0.1"
        }
    ]
}

Ubuntu:22.04:LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:deb/ubuntu/python-setuptools@44.1.1-1.2ubuntu0.22.04.1?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
44.1.1-1.2ubuntu0.22.04.1

Affected versions

44.*

44.1.1-1
44.1.1-1.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "pypy-setuptools": "44.1.1-1.2ubuntu0.22.04.1",
            "pypy-pkg-resources": "44.1.1-1.2ubuntu0.22.04.1",
            "python-setuptools": "44.1.1-1.2ubuntu0.22.04.1",
            "python2-setuptools-whl": "44.1.1-1.2ubuntu0.22.04.1",
            "python-pkg-resources": "44.1.1-1.2ubuntu0.22.04.1"
        }
    ]
}

Ubuntu:22.04:LTS / setuptools

Package

Name
setuptools
Purl
pkg:deb/ubuntu/setuptools@59.6.0-1.2ubuntu0.22.04.1?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.6.0-1.2ubuntu0.22.04.1

Affected versions

52.*

52.0.0-4

58.*

58.2.0-1

59.*

59.6.0-1.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-setuptools-whl": "59.6.0-1.2ubuntu0.22.04.1",
            "python3-setuptools": "59.6.0-1.2ubuntu0.22.04.1",
            "python-setuptools-doc": "59.6.0-1.2ubuntu0.22.04.1",
            "python3-pkg-resources": "59.6.0-1.2ubuntu0.22.04.1"
        }
    ]
}