Логотип exploitDog
bind:"BDU:2025-09687" OR bind:"CVE-2025-8194"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-09687" OR bind:"CVE-2025-8194"

Количество 35

Количество 35

fstec логотип

BDU:2025-09687

6 месяцев назад

Уязвимость модуля tarfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-8194

6 месяцев назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-8194

6 месяцев назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-8194

6 месяцев назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-8194

4 месяца назад

Tarfile infinite loop during parsing with negative member offset

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-8194

6 месяцев назад

There is a defect in the CPython \u201ctarfile\u201d module affecting ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03032-1

5 месяцев назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02984-1

5 месяцев назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02983-1

5 месяцев назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02982-1

5 месяцев назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02948-1

5 месяцев назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02701-1

5 месяцев назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02700-1

5 месяцев назад

Security update for python39

EPSS: Низкий
rocky логотип

RLSA-2025:15019

3 месяца назад

Moderate: python3.9 security update

EPSS: Низкий
rocky логотип

RLSA-2025:15010

3 месяца назад

Moderate: python3.11 security update

EPSS: Низкий
rocky логотип

RLSA-2025:15007

3 месяца назад

Moderate: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:14984

3 месяца назад

Moderate: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:14841

4 месяца назад

Moderate: python3.11 security update

EPSS: Низкий
rocky логотип

RLSA-2025:14546

4 месяца назад

Moderate: python3.12 security update

EPSS: Низкий
github логотип

GHSA-v594-44hm-2j7p

6 месяцев назад

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: import tarfile def _block_patched(self, count):     if count < 0: # pragma: no cover         raise tarfile.InvalidHeaderError("invalid offset")     return _block_patched._orig_block(self, count) _block_patched._orig_block = tarfile.TarInfo._block tarfile.TarInfo._block = _block_patched

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-09687

Уязвимость модуля tarfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module:  https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVSS3: 7.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-8194

Tarfile infinite loop during parsing with negative member offset

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-8194

There is a defect in the CPython \u201ctarfile\u201d module affecting ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03032-1

Security update for python

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02984-1

Security update for python311

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02983-1

Security update for python36

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02982-1

Security update for python312

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02948-1

Security update for python310

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02701-1

Security update for python

0%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02700-1

Security update for python39

0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2025:15019

Moderate: python3.9 security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:15010

Moderate: python3.11 security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:15007

Moderate: python3.12 security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:14984

Moderate: python3.12 security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:14841

Moderate: python3.11 security update

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2025:14546

Moderate: python3.12 security update

0%
Низкий
4 месяца назад
github логотип
GHSA-v594-44hm-2j7p

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: import tarfile def _block_patched(self, count):     if count < 0: # pragma: no cover         raise tarfile.InvalidHeaderError("invalid offset")     return _block_patched._orig_block(self, count) _block_patched._orig_block = tarfile.TarInfo._block tarfile.TarInfo._block = _block_patched

CVSS3: 7.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу