Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20907

Опубликовано: 13 июл. 2020
Источник: debian
EPSS Низкий

Описание

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.9fixed3.9.0~b5-1package
python3.8fixed3.8.5-1package
python3.7removedpackage
python3.7fixed3.7.3-2+deb10u2busterpackage
python3.5removedpackage
python2.7fixed2.7.18-2package
pypy3fixed7.3.3+dfsg-1package

Примечания

  • https://bugs.python.org/issue39017

  • https://github.com/python/cpython/commit/5a8d121a1f3ef5ad7c105ee378cc79a3eac0c7d4 (master)

  • https://github.com/python/cpython/commit/f3232294ee695492f43d424cc6969d018d49861d (3.9-branch)

  • https://github.com/python/cpython/commit/c55479556db015f48fc8bbca17f64d3e65598559 (3.8-branch)

  • https://github.com/python/cpython/commit/79c6b602efc9a906c8496f3d5f4d54c54b48fa06 (3.7-branch)

  • https://github.com/python/cpython/commit/47a2955589bdb1a114d271496ff803ad73f954b8 (3.6-branch)

  • https://github.com/python/cpython/pull/21454

EPSS

Процентиль: 55%
0.00321
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
redhat
больше 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
nvd
почти 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

suse-cvrf
почти 5 лет назад

Security update for python3

EPSS

Процентиль: 55%
0.00321
Низкий