Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc97-8p9q-cf27

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

Ссылки

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
redhat
больше 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
nvd
почти 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
почти 5 лет назад

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craf ...

EPSS

Процентиль: 55%
0.00321
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-835