—
PYSEC-2021-427
Quick fix
PYSEC-2021-427 — mpmath: upgrade to the fixed version with the command below.
pip install --upgrade 'mpmath>=46d44c3c8f3244017fe1eb102d564eb4ab8ef750'Details
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 when the mpmathify function is called.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mpmath
Introduced in:
0Fixed in: 46d44c3c8f3244017fe1eb102d564eb4ab8ef750Fix
pip install --upgrade 'mpmath>=46d44c3c8f3244017fe1eb102d564eb4ab8ef750'References
- https://github.com/npm/hosted-git-info/pull/76[WEB]
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29063/Mpmath.md[WEB]
- https://github.com/yetingli/SaveResults/blob/main/js/hosted-git-info.js[WEB]
- https://www.npmjs.com/package/hosted-git-info[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MS2U6GLXQSRZJE2HVUAUMVFR2DWQLCZG/[WEB]
- https://github.com/fredrik-johansson/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750[FIX]
- https://github.com/advisories/GHSA-f865-m6cq-j9vx[ADVISORY]