ALAS2-2021-1688


Amazon Linux 2 Security Advisory: ALAS-2021-1688
Advisory Release Date: 2021-07-14 20:40 Pacific
Advisory Updated Date: 2021-07-15 21:41 Pacific
Severity: Medium

Issue Overview:

A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability. (CVE-2021-33503)


Affected Packages:

python-urllib3


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update python-urllib3 to update your system.

New Packages:
noarch:
    python-urllib3-1.25.9-1.amzn2.0.2.noarch

src:
    python-urllib3-1.25.9-1.amzn2.0.2.src