PT-2017-4256 · Marked · Marked
Published
2017-09-07
·
Updated
2019-10-09
·
CVE-2017-16114
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
marked versions prior to 0.3.9
Description
The issue is related to incorrect handling of regular expressions in the marked module, which can lead to a denial of service. This can cause the event loop to be blocked, with significant amplification - 1,000 characters can result in a blockage of around 6 seconds.
Recommendations
Update to version 0.3.9 or later.
As a temporary workaround, consider restricting the input size to prevent excessive blocking of the event loop until a patch is available.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Marked