Описание
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| azl3 python3 3.12.14-1 on Azure Linux 3.0 | ||
| azl3 python3 3.12.9-14 on Azure Linux 3.0 |
Показывать по
EPSS
Связанные уязвимости
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
When decompressing crafted zip files using the bzip/LZMA/Zstandard c ...
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
EPSS