Junglewise Threat Intelligence

CVE-2022-3371: PYSEC-2022-299 - Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

CVE-2022-3371 · Severity: low · CVSS 3.1 · Published 2022-09-30

Technologies: rdiffweb (PyPI). Vendors: PyPI.

Executive brief

rdiffweb is a web-based backup client and server used to manage incremental file backups. Due to a lack of length validation on token names, an attacker can submit an extremely long token name that causes the application to allocate excessive memory, resulting in denial of service or memory corruption that crashes the service.

Technical details

rdiffweb prior to version 2.5.0a3 contains an Allocation of Resources Without Limits or Throttling vulnerability (CWE-770) in its token name parameter. The application fails to enforce a maximum length limit on the token name field, allowing an attacker to send a request with an excessively long token name. This causes uncontrolled memory allocation, leading to denial of service or potential memory corruption. The vulnerability requires network access but no authentication, allowing unauthenticated remote attackers to trigger the issue. The fix limits the length of token name and fullname fields, mitigating resource exhaustion.

Affected products

  • rdiffweb rdiffweb before 2.5.0a3

Timeline

  • 2022-10-01: disclosed
  • 2022-10-01: patched: Version 2.5.0a3 fixes the issue

References

Related threats