Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm46-725r-hh9v

Опубликовано: 19 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

An issue was found in the CPython zipfile module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.

The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

An issue was found in the CPython zipfile module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.

The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

EPSS

Процентиль: 39%
0.00173
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-405

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

CVSS3: 6.2
redhat
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

CVSS3: 6.2
nvd
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

CVSS3: 6.2
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 6.2
debian
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions ...

EPSS

Процентиль: 39%
0.00173
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-405