Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-0450

Опубликовано: 19 мар. 2024
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

An issue was found in the CPython zipfile module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

A flaw was found in the Python/CPython 'zipfile' that can allow a zip-bomb type of attack. An attacker may craft a zip file format, leading to a Denial of Service when processed.

Отчет

Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10python3.12Not affected
Red Hat Enterprise Linux 6pythonNot affected
Red Hat Enterprise Linux 7pythonOut of support scope
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8gimp:flatpak/python2Not affected
Red Hat Enterprise Linux 8inkscape:flatpak/python2Not affected
Red Hat Enterprise Linux 8python27:2.7/python2Not affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python3FixedRHSA-2024:334723.05.2024
Red Hat Enterprise Linux 8python39FixedRHSA-2024:346629.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-450
https://bugzilla.redhat.com/show_bug.cgi?id=2276525python: The zipfile module is vulnerable to zip-bombs leading to denial of service

EPSS

Процентиль: 39%
0.00173
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

CVSS3: 6.2
nvd
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

CVSS3: 6.2
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 6.2
debian
больше 1 года назад

An issue was found in the CPython `zipfile` module affecting versions ...

suse-cvrf
около 1 года назад

Security update for python

EPSS

Процентиль: 39%
0.00173
Низкий

6.2 Medium

CVSS3