Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6232

Опубликовано: 03 сент. 2024
Источник: debian
EPSS Низкий

Описание

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.13fixed3.13.0~rc2-1package
python3.12fixed3.12.6-1package
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u4bookwormpackage
python3.9removedpackage
python2.7removedpackage
python2.7ignoredbullseyepackage

Примечания

  • https://github.com/python/cpython/issues/121285

  • https://github.com/python/cpython/pull/121286

  • https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373 (v3.13.0rc2)

  • https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06 (v3.12.6)

  • https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf (v3.11.10)

  • https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4 (v3.10.15)

EPSS

Процентиль: 71%
0.00716
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
redhat
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
nvd
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

suse-cvrf
9 месяцев назад

Security update for python36

EPSS

Процентиль: 71%
0.00716
Низкий