USN-7040-1: ConfigObj vulnerability
Published Sep 26, 2024
·Updated
It was discovered that ConfigObj contains regex that is susceptible to catastrophic backtracking. An attacker could possibly use this issue to cause a regular expression denial of service.
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/python3-configobj<5.0.6-5ubuntu0.1
5.0.6-5ubuntu0.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/python3-configobj<5.0.6-4ubuntu0.1
5.0.6-4ubuntu0.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/python-configobj<5.0.6-2ubuntu0.18.04.1~esm1
5.0.6-2ubuntu0.18.04.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python3-configobj<5.0.6-2ubuntu0.18.04.1~esm1
5.0.6-2ubuntu0.18.04.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/python-configobj<5.0.6-2ubuntu0.16.04.1~esm1
5.0.6-2ubuntu0.16.04.1~esm1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/python3-configobj<5.0.6-2ubuntu0.16.04.1~esm1
5.0.6-2ubuntu0.16.04.1~esm1
Ubuntu Ubuntu=16.04
Event History
Sep 26, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7040-1?
USN-7040-1 has a medium severity level due to the potential for regular expression denial of service.
2
How do I fix USN-7040-1?
To fix USN-7040-1, upgrade the python3-configobj package to version 5.0.6-5ubuntu0.1 or a later version depending on your Ubuntu release.
3
Which versions of Ubuntu are affected by USN-7040-1?
USN-7040-1 affects Ubuntu 22.04, 20.04, 18.04, and 16.04.
4
What is the nature of the vulnerability in USN-7040-1?
The vulnerability in USN-7040-1 is related to catastrophic backtracking in regex, which can lead to denial of service.
5
Is there a CVE associated with USN-7040-1?
Yes, USN-7040-1 is associated with CVE-2023-26112.