ELA-1341-1 sqlparse security update

denial of service

2025-03-08
Packagesqlparse
Version0.1.13-2+deb8u1 (jessie), 0.2.2-1+deb9u2 (stretch), 0.2.4-1+deb10u2 (buster)
Related CVEs CVE-2024-4340


Uriya Yavniely discovered that passing a heavily nested list to sqlparse.parse() may raise a RecursionError exception, which may lead to denial of service.

A generic SQLParseError is now raised instead.



For Debian 10 buster, these problems have been fixed in version 0.2.4-1+deb10u2.

For Debian 8 jessie, these problems have been fixed in version 0.1.13-2+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 0.2.2-1+deb9u2.

We recommend that you upgrade your sqlparse packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.