Bug 2250364 (CVE-2023-26364) - CVE-2023-26364 css-tools: Improper Input Validation causes Denial of Service via Regular Expression
Summary: CVE-2023-26364 css-tools: Improper Input Validation causes Denial of Service ...
Keywords:
Status: NEW
Alias: CVE-2023-26364
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2250366 2250367 2306484
Blocks: 2250363
TreeView+ depends on / blocked
 
Reported: 2023-11-17 21:58 UTC by Patrick Del Bello
Modified: 2025-04-01 08:28 UTC (History)
61 users (show)

Fixed In Version: css-tools 4.3.1
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2024:3316 0 None None None 2024-05-23 06:39:41 UTC
Red Hat Product Errata RHSA-2024:3919 0 None None None 2024-06-13 11:38:29 UTC
Red Hat Product Errata RHSA-2024:3989 0 None None None 2024-06-20 00:35:48 UTC
Red Hat Product Errata RHSA-2024:8676 0 None None None 2024-10-30 14:25:59 UTC
Red Hat Product Errata RHSA-2025:0082 0 None None None 2025-01-08 11:31:25 UTC
Red Hat Product Errata RHSA-2025:0164 0 None None None 2025-01-09 11:28:15 UTC
Red Hat Product Errata RHSA-2025:0323 0 None None None 2025-01-15 01:20:08 UTC

Description Patrick Del Bello 2023-11-17 21:58:50 UTC
@adobe/css-tools version 4.3.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a minor denial of service while attempting to parse CSS. Exploitation of this issue does not require user interaction or privileges.

https://github.com/adobe/css-tools/security/advisories/GHSA-hpx4-r86g-5jrg

Comment 2 errata-xmlrpc 2024-05-23 06:39:37 UTC
This issue has been addressed in the following products:

  MTA-7.0-RHEL-9
  MTA-7.0-RHEL-8

Via RHSA-2024:3316 https://access.redhat.com/errata/RHSA-2024:3316

Comment 3 errata-xmlrpc 2024-06-13 11:38:25 UTC
This issue has been addressed in the following products:

  Migration Toolkit for Runtimes 1 on RHEL 8

Via RHSA-2024:3919 https://access.redhat.com/errata/RHSA-2024:3919

Comment 4 errata-xmlrpc 2024-06-20 00:35:44 UTC
This issue has been addressed in the following products:

  MTA-6.2-RHEL-9
  MTA-6.2-RHEL-8

Via RHSA-2024:3989 https://access.redhat.com/errata/RHSA-2024:3989

Comment 5 errata-xmlrpc 2024-10-30 14:25:56 UTC
This issue has been addressed in the following products:

  RHODF-4.17-RHEL-9

Via RHSA-2024:8676 https://access.redhat.com/errata/RHSA-2024:8676

Comment 6 errata-xmlrpc 2025-01-08 11:31:21 UTC
This issue has been addressed in the following products:

  RHODF-4.16-RHEL-9

Via RHSA-2025:0082 https://access.redhat.com/errata/RHSA-2025:0082

Comment 7 errata-xmlrpc 2025-01-09 11:28:11 UTC
This issue has been addressed in the following products:

  RHODF-4.15-RHEL-9

Via RHSA-2025:0164 https://access.redhat.com/errata/RHSA-2025:0164

Comment 8 errata-xmlrpc 2025-01-15 01:20:05 UTC
This issue has been addressed in the following products:

  RHODF-4.14-RHEL-9

Via RHSA-2025:0323 https://access.redhat.com/errata/RHSA-2025:0323


Note You need to log in before you can comment on or make changes to this bug.