Количество 33
Количество 33
ELSA-2023-7024
ELSA-2023-7024: python3.11 security update (MODERATE)
ELSA-2023-6494
ELSA-2023-6494: python3.11 security update (MODERATE)
CVE-2023-41105
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
CVE-2023-41105
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
CVE-2023-41105
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
CVE-2023-41105
An issue was discovered in Python 3.11 through 3.11.4. If a path conta ...
CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
CVE-2007-4559
CVE-2007-4559
Directory traversal vulnerability in the (1) extract and (2) extractal ...
GHSA-65fx-pmw6-rcfm
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
BDU:2024-09261
Уязвимость функции os.path.normpath() интерпретатора языка программирования Python, связанная с обходом списка разрешений при усечении пути посредством вставки нулевого байта, позволяющая нарушителю нарушить целостность защищаемой информации
SUSE-SU-2023:2778-1
Security update for python311
SUSE-SU-2023:2641-1
Security update for python39
SUSE-SU-2023:2517-1
Security update for python3
SUSE-SU-2023:2473-1
Security update for python36
SUSE-SU-2023:2463-1
Security update for python310
GHSA-gw9q-c7gh-j9vm
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
ELSA-2023-7176
ELSA-2023-7176: python-pip security update (MODERATE)
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
ELSA-2023-7024 ELSA-2023-7024: python3.11 security update (MODERATE)  | почти 2 года назад | |||
ELSA-2023-6494 ELSA-2023-6494: python3.11 security update (MODERATE)  | почти 2 года назад | |||
CVE-2023-41105 An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.  | CVSS3: 7.5  | 0% Низкий | около 2 лет назад | |
CVE-2023-41105 An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.  | CVSS3: 7.5  | 0% Низкий | около 2 лет назад | |
CVE-2023-41105 An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.  | CVSS3: 7.5  | 0% Низкий | около 2 лет назад | |
CVE-2023-41105 An issue was discovered in Python 3.11 through 3.11.4. If a path conta ...  | CVSS3: 7.5  | 0% Низкий | около 2 лет назад | |
CVE-2007-4559 Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.  | CVSS3: 9.8  | 86% Высокий | около 18 лет назад | |
CVE-2007-4559 Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.  | CVSS3: 5.5  | 86% Высокий | около 18 лет назад | |
CVE-2007-4559 Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.  | CVSS3: 9.8  | 86% Высокий | около 18 лет назад | |
CVSS3: 9.8  | 86% Высокий | около 1 года назад | ||
CVE-2007-4559 Directory traversal vulnerability in the (1) extract and (2) extractal ...  | CVSS3: 9.8  | 86% Высокий | около 18 лет назад | |
GHSA-65fx-pmw6-rcfm An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.  | CVSS3: 7.5  | 0% Низкий | около 2 лет назад | |
BDU:2024-09261 Уязвимость функции os.path.normpath() интерпретатора языка программирования Python, связанная с обходом списка разрешений при усечении пути посредством вставки нулевого байта, позволяющая нарушителю нарушить целостность защищаемой информации  | CVSS3: 7.5  | 0% Низкий | больше 2 лет назад | |
SUSE-SU-2023:2778-1 Security update for python311  | 86% Высокий | больше 2 лет назад | ||
SUSE-SU-2023:2641-1 Security update for python39  | 86% Высокий | больше 2 лет назад | ||
SUSE-SU-2023:2517-1 Security update for python3  | 86% Высокий | больше 2 лет назад | ||
SUSE-SU-2023:2473-1 Security update for python36  | 86% Высокий | больше 2 лет назад | ||
SUSE-SU-2023:2463-1 Security update for python310  | 86% Высокий | больше 2 лет назад | ||
GHSA-gw9q-c7gh-j9vm Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.  | CVSS3: 9.8  | 86% Высокий | больше 3 лет назад | |
ELSA-2023-7176 ELSA-2023-7176: python-pip security update (MODERATE)  | почти 2 года назад | 
Уязвимостей на страницу