Your message dated Sat, 02 Mar 2024 06:50:40 +0000
with message-id <[email protected]>
and subject line Bug#1063538: fixed in python-multipart 0.0.9-1
has caused the Debian Bug report #1063538,
regarding python-multipart: CVE-2024-24762
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1063538: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1063538
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-multipart
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for python-multipart.

CVE-2024-24762[0]:
| FastAPI is a web framework for building APIs with Python 3.8+ based
| on standard Python type hints. When using form data, `python-
| multipart` uses a Regular Expression to parse the HTTP `Content-
| Type` header, including options. An attacker could send a custom-
| made `Content-Type` option that is very difficult for the RegEx to
| process, consuming CPU resources and stalling indefinitely (minutes
| or more) while holding the main event loop. This means that process
| can't handle any more requests. It's a ReDoS(Regular expression
| Denial of Service), it only applies to those reading form data,
| using `python-multipart`. This vulnerability has been patched in
| version 0.109.0.

This was reported by fastapi:
https://github.com/tiangolo/fastapi/security/advisories/GHSA-qf9m-vfgh-m389

But the actual code fix within Debian is in python-multipart:
https://github.com/Kludex/python-multipart/commit/20f0ef6b4e4caf7d69a667c54dff57fe467109a4
https://github.com/Kludex/python-multipart/pull/75


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-24762
    https://www.cve.org/CVERecord?id=CVE-2024-24762

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: python-multipart
Source-Version: 0.0.9-1
Done: Sandro Tosi <[email protected]>

We believe that the bug you reported is fixed in the latest version of
python-multipart, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sandro Tosi <[email protected]> (supplier of updated python-multipart package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sat, 02 Mar 2024 01:28:50 -0500
Source: python-multipart
Architecture: source
Version: 0.0.9-1
Distribution: unstable
Urgency: high
Maintainer: Sandro Tosi <[email protected]>
Changed-By: Sandro Tosi <[email protected]>
Closes: 1063538
Changes:
 python-multipart (0.0.9-1) unstable; urgency=high
 .
   [ Piotr Ożarowski ]
   * Team upload
   * New upstream release
     - fixes CVE-2024-24762 (Closes: #1063538)
 .
   [ Sandro Tosi ]
   * drop DPT
Checksums-Sha1:
 9a3178930498d7ec305f50b9a3fa3fa49eb649a0 2174 python-multipart_0.0.9-1.dsc
 159390da776e3d32dd6d9cf9c9218ce2d6e206d4 49448 
python-multipart_0.0.9.orig.tar.gz
 2ba5b3f7fd59f2c9f4a72c39e4f4bd57154be16c 2860 
python-multipart_0.0.9-1.debian.tar.xz
 e5c676d1e83851c5a78e0bb8c344d1b8b13a573f 8047 
python-multipart_0.0.9-1_source.buildinfo
Checksums-Sha256:
 9caa86c80e6fa9d88ce6da074ad772d90c79bc54290c73864d436bf22b045a0d 2174 
python-multipart_0.0.9-1.dsc
 71c887316d8a26f34e56f08ab7ef557ca4d7c04871a2aabb37dbe2854461955f 49448 
python-multipart_0.0.9.orig.tar.gz
 8c664b49a0319f89791ce5a9538d2a940e43cdb452d783a601b07527db3e7b31 2860 
python-multipart_0.0.9-1.debian.tar.xz
 2008a7927cf6408a22da6de809fe7f8d58ed742f9653108f3202beef555d1981 8047 
python-multipart_0.0.9-1_source.buildinfo
Files:
 7f91227c76617ca39fc0634c703c4fc3 2174 python optional 
python-multipart_0.0.9-1.dsc
 766c34ec75af19a37b41446d993a7f68 49448 python optional 
python-multipart_0.0.9.orig.tar.gz
 c7c46bc08c528238ac500af66bd06c4c 2860 python optional 
python-multipart_0.0.9-1.debian.tar.xz
 1bf3dd12406f30f3e4f289c347ea2a2c 8047 python optional 
python-multipart_0.0.9-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEufrTGSrz5KUwnZ05h588mTgBqU8FAmXixzQACgkQh588mTgB
qU9fzBAAtlf5cTyd+IQQnEXGwbzdhaH26cI8kol8yUDss56pQULtKpAgXkOzMQPm
XqoEvB2ULYPrKQ+K7SgNOVjmX9rSnYZyhdJW/QgxMCkTLVULfxaartQRkTuIXnLm
MFLNOjtUri5AGx9S09RAc8sTH+A8mjYItcqF6CDm5r+pzj9SLEAtHCb3WQa0ftGD
Ws7zz44l2T/k78zdND2pTFUpxVyGiUtJS+HzcWrSS11UleuvGPqZD11/8qDxwnrF
6crk9rxhUDfaO8b4i3jGfQD9xyNNPyp+/5RjKzfKDPuVChPcJ7IlTwqxjFJ9UDle
g3LhC0Fdkd6P7UN0g+ImuB+qBdffDisrgwmwsFX1sTq4IKp2iTcmSD1x0YDtFuvX
HWDarDdElaUJwKQpvkWsTRYEf7TZLOUg6gVfRgqeGMWJeILlAS8L/1lUy+dSTWHu
9lJOWhnyw5kvlwgCZ53DxuiG1gqENw5eYQofilpRCRuuisfj7yhwFzH5E+e4WDBi
ZqaIZ/1Na42//XAHEePN01+kwGSCZV+1Eb95/9QNQqgDzFcqHIW6gFnla56KrtJp
8JQMUnh1gfhmETut0r512I7+tTgdiDBBVmdV1H7RZm+McMtoGPpS6HKwVbClglxX
vGlxvvspyKDMqIXqDpP+YxYOOMV0QCdTfa7IP0y+4q7f+OHfIM0=
=03Jv
-----END PGP SIGNATURE-----

Attachment: pgpUrGygI6Wgx.pgp
Description: PGP signature


--- End Message ---

Reply via email to