ALAS2-2021-1688

Related Vulnerabilities: CVE-2021-33503  

A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability. (CVE-2021-33503)

ALAS2-2021-1688


Amazon Linux 2 Security Advisory: ALAS-2021-1688
Advisory Release Date: 2021-07-14 20:40 Pacific
Advisory Updated Date: 2021-07-15 21:41 Pacific
Severity: Medium
References: CVE-2021-33503 

Issue Overview:

A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability. (CVE-2021-33503)


Affected Packages:

python-urllib3


Issue Correction:
Run yum update python-urllib3 to update your system.

New Packages:
noarch:
    python-urllib3-1.25.9-1.amzn2.0.2.noarch

src:
    python-urllib3-1.25.9-1.amzn2.0.2.src