Repository navigation
REDoS in parseentities #86087
Description
Activity
Hi,
I find this regex '<!ENTITY +(\w+) +CDATA +"([^"]+)" +-- +((?:.|\n)+?) *-->' may be stucked by input.
The vulnerable regex is located in
cpython/Tools/scripts/parseentities.py
Line 18 in 8d21aa2
entityRE = re.compile('<!ENTITY +(\w+) +CDATA +"([^"]+)" +-- +((?:.|\n)+?) *-->') The ReDOS vulnerability of the regex is mainly due to the sub-pattern ' +((?:.|\n)+?) *'
and can be exploited with the following string
'<!ENTITY a CDATA "a" -- ' + ' ' * 5000You can execute the following code to reproduce ReDos
from Tools.scripts.parseentities import parse from time import perf_counter for i in range(0, 10000): ATTACK = '<!ENTITY a CDATA "a" -- ' + ' ' * i * 100 LEN = len(ATTACK) BEGIN = perf_counter() parse(ATTACK) DURATION = perf_counter() - BEGIN print(f"{LEN}: took {DURATION} seconds!")
Looking forward for your response!
Best,
Yeting Li- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life
on Oct 3, 2020 Without evaluating the validity of the regex vulnerability, is important to note that the files in Tools/scripts are not part of the standard library and therefore they aren't a valid stack vector.
- added3.11only security fixesonly security fixesand removed3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life
on Dec 6, 2021 Interesting that the tool still exists. It uses mxTextTools, but in a non-packaged version, so it's been broken for two decades now :-)
I think it's safe to remove it from Tools\scripts.
Tools/scripts/parseentities.pyhas been removed in #92504.Reacted by Hugo van Kemenade
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: