Bug 2164147 (CVE-2023-24038) - CVE-2023-24038 perl-HTML-StripScripts: Handler for style attribute is vulnerable to ReDoS
Summary: CVE-2023-24038 perl-HTML-StripScripts: Handler for style attribute is vulnera...
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2023-24038
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2164148 2164149 2164150 2164151
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-01-24 18:09 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-01-27 02:22 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-01-27 02:22:11 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2023-01-24 18:09:51 UTC
The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

Reference:
https://github.com/clintongormley/perl-html-stripscripts/issues/3

Comment 1 Guilherme de Almeida Suckevicz 2023-01-24 18:10:14 UTC
Created perl-HTML-StripScripts tracking bugs for this issue:

Affects: epel-all [bug 2164149]
Affects: fedora-all [bug 2164148]


Created perl-HTML-StripScripts-Parser tracking bugs for this issue:

Affects: epel-all [bug 2164151]
Affects: fedora-all [bug 2164150]

Comment 2 Product Security DevOps Team 2023-01-27 02:22:09 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.