Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-9674

Опубликовано: 11 мар. 2019
Источник: redhat
CVSS3: 4.2

Описание

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

A ZIP bomb attack was found in the Python zipfile module. A remote attacker could abuse this flaw by providing a specially crafted ZIP file that, when decompressed by zipfile, would exhaust system resources resulting in a denial of service.

Отчет

There is no plan to fix this flaw. Programs using the Python zipfile module should be responsible for validating external untrusted ZIP files. For further details, please refer to the following URLs: [1] https://docs.python.org/dev/library/zipfile.html#decompression-pitfalls [2] https://python-security.readthedocs.io/security.html#archives-and-zip-bomb

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonWill not fix
Red Hat Enterprise Linux 6pythonWill not fix
Red Hat Enterprise Linux 7pythonWill not fix
Red Hat Enterprise Linux 7python3Will not fix
Red Hat Enterprise Linux 8python27:2.7/python2Will not fix
Red Hat Enterprise Linux 8python3Will not fix
Red Hat Enterprise Linux 8python36:3.6/python36Will not fix
Red Hat Software Collectionspython27-pythonWill not fix
Red Hat Software Collectionsrh-python36-pythonWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=1800749python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

CVSS3: 7.5
nvd
больше 5 лет назад

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 5 лет назад

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to caus ...

CVSS3: 7.5
github
около 3 лет назад

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

4.2 Medium

CVSS3