Your message dated Fri, 19 Apr 2024 05:49:20 +0000
with message-id <[email protected]>
and subject line Bug#1067177: fixed in black 24.4.0-1
has caused the Debian Bug report #1067177,
regarding black: CVE-2024-21503
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1067177: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067177
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: black
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for black.
CVE-2024-21503[0]:
| Versions of the package black before 24.3.0 are vulnerable to
| Regular Expression Denial of Service (ReDoS) via the
| lines_with_leading_tabs_expanded function in the strings.py file. An
| attacker could exploit this vulnerability by crafting a malicious
| input that causes a denial of service. Exploiting this
| vulnerability is possible when running Black on untrusted input, or
| if you habitually put thousands of leading tab characters in your
| docstrings.
https://security.snyk.io/vuln/SNYK-PYTHON-BLACK-6256273
https://github.com/psf/black/releases/tag/24.3.0
https://github.com/psf/black/commit/f00093672628d212b8965a8993cee8bedf5fe9b8
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-21503
https://www.cve.org/CVERecord?id=CVE-2024-21503
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: black
Source-Version: 24.4.0-1
Done: Julian Gilbey <[email protected]>
We believe that the bug you reported is fixed in the latest version of
black, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Julian Gilbey <[email protected]> (supplier of updated black package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 19 Apr 2024 06:26:09 +0100
Source: black
Architecture: source
Version: 24.4.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Julian Gilbey <[email protected]>
Closes: 1067177 1067466
Changes:
black (24.4.0-1) unstable; urgency=medium
.
* Team upload
* New upstream release, fixes CVE-2024-21503 (closes: #1067177)
* Drop defunct python3-typed-ast from autopkgtest dependencies
(closes: #1067466)
* Update Standards-Version (no changes needed)
Checksums-Sha1:
cc446a0b4fe05b159baf5f9682b7409ab68c93eb 2866 black_24.4.0-1.dsc
2ea93b6e06a451ca5d588d55cb43546bd72bef3b 1255404 black_24.4.0.orig.tar.gz
c4a593bfea467b1502baff90cadd392401a4ec3b 10976 black_24.4.0-1.debian.tar.xz
da13000dcdb730bd72815f42dc57882ee4e1188c 9222 black_24.4.0-1_amd64.buildinfo
Checksums-Sha256:
e36a2056c64a2bb056f44f63dfea482b9294430f51376ddb54dd71369605c34e 2866
black_24.4.0-1.dsc
b9997dd5ae71ca0e948de13250d33ccd0ef1feec0394801f59cdb1ab1026881f 1255404
black_24.4.0.orig.tar.gz
5c000a995515ee17e03f928def37baba5d6198fa5d1b3f3373e56927c9459878 10976
black_24.4.0-1.debian.tar.xz
c08f2875e71bd46ccb987fda2c1fa616f75accfaa0d737a85097673d51ff9384 9222
black_24.4.0-1_amd64.buildinfo
Files:
ee9c8f591b19fb00f3bdcab38a16a841 2866 python optional black_24.4.0-1.dsc
3ae2f91d4220b4a06ef4a3d53854a342 1255404 python optional
black_24.4.0.orig.tar.gz
9eca3d900288f3bc4eb389b2186f7fc1 10976 python optional
black_24.4.0-1.debian.tar.xz
7a5afb9a082bb93a295882efc3353bb8 9222 python optional
black_24.4.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJDBAEBCAAtFiEEfhrD+iemSShMMj72aVxCkxbAe/4FAmYiAT0PHGpkZ0BkZWJp
YW4ub3JnAAoJEGlcQpMWwHv+TLwP/Rj2uuas59fIA6DtuOn21SPR62NCnbXUCJ3Y
XdT3nK77kEJeFsf/YFdbOz9aOO9UurrSIZsEmM4p4dZV4RAUnW7f3yJ4i9BSD67u
IF5dI9WP0XcX97snVCyEcP0mh1lDE9Wz1+3dxandNnrIqsEhjdg+iYD+yEvTmlPy
kTM75vtWtPKBT/eYSIu2YknB5STodX1xHju4mo2lymwvSMJXBmobxZvVOP2kEtiG
xlKBQo98H5QuWQHW63t/Ai3aPaTaqZfF2s9y+4bfQU93MhEKNq9ZGj+M4rQ/OmBC
2lAZjLHLPwp0L2mxjrZckA7jpTRJeiwjS7UhrMSfvtaxPRili2yKIRkYpUmwZefm
fhTSxQwurpXmSZ8bYaPOiAgXI7uzCsM2I/D+jSidOdDYZ4tpsDNzpqXYstiixIzg
kjLCY+HSlVirEb+gVG0xf1/akC/pIIvjNKwL7ZEPcbsgPwi9y34pFP9Un3/aHsTp
6zc+y86BZRJijBzg0miw27YtucgOiyTQLsjBh5+cihpaFmvLIwWLrrfO3Y3giJ1I
Ht2XhJjI/L4oiJ3gp3WvMPsHQN25wV97xecIxj2XAqxD3KUsGnYURRxkl1ep3oWM
5eLdlYKT6wxU4aWCD2BdI6hXagj6GDv6FpLsXf9vadB/8yrHLXZtp5FJ1I0R8UpV
D3OS3pxk
=g4/t
-----END PGP SIGNATURE-----
pgp3PCG7TTAhi.pgp
Description: PGP signature
--- End Message ---