fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-2465 fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.
Github GHSA Github GHSA GHSA-2m96-52r3-2f3g fugit parse and parse_nat stall on lengthy input
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Sep 2024 00:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:floraison:fugit:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 Aug 2024 22:00:00 +0900

Type Values Removed Values Added
First Time appeared Floraison
Floraison fugit
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:floraison:fugit:*:*:*:*:*:ruby:*:*
Vendors & Products Floraison
Floraison fugit

Wed, 21 Aug 2024 06:30:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 19 Aug 2024 23:45:00 +0900

Type Values Removed Values Added
Description fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.
Title fugit parse and parse_nat stall on lengthy input
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-03T15:03:00.904Z

Reserved: 2024-08-09T14:23:55.514Z

Link: CVE-2024-43380

cve-icon Vulnrichment

Updated: 2024-09-03T15:02:55.999Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-19T15:15:08.893

Modified: 2024-08-21T12:38:00.247

Link: CVE-2024-43380

cve-icon Redhat

Severity : Low

Publid Date: 2024-08-19T00:00:00Z

Links: CVE-2024-43380 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses