VDB
Sign up
—

PYSEC-2022-243

Quick fix

PYSEC-2022-243 — untangle: upgrade to the fixed version with the command below.

pip install --upgrade 'untangle>=1.2.1'

Details

untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/untangle
Introduced in: 0Fixed in: 1.2.1
Fixpip install --upgrade 'untangle>=1.2.1'

References