PT-2017-4256 · Marked · Marked

Published

2017-09-07

·

Updated

2019-10-09

·

CVE-2017-16114

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions marked versions prior to 0.3.9
Description The issue is related to incorrect handling of regular expressions in the marked module, which can lead to a denial of service. This can cause the event loop to be blocked, with significant amplification - 1,000 characters can result in a blockage of around 6 seconds.
Recommendations Update to version 0.3.9 or later. As a temporary workaround, consider restricting the input size to prevent excessive blocking of the event loop until a patch is available.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07555
CVE-2017-16114
GHSA-X5PG-88WF-QQ4P

Affected Products

Marked