Логотип exploitDog
bind:CVE-2025-8291
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-8291

Количество 35

Количество 35

ubuntu логотип

CVE-2025-8291

6 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2025-8291

6 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-8291

6 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2025-8291

6 месяцев назад

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-8291

6 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4313-1

4 месяца назад

Security update for python

EPSS: Низкий
rocky логотип

RLSA-2025:23940

3 месяца назад

Moderate: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:23323

3 месяца назад

Moderate: python3.12 security update

EPSS: Низкий
github логотип

GHSA-49g5-f6qw-8mm7

6 месяцев назад

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23940

3 месяца назад

ELSA-2025-23940: python3.12 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-23323

3 месяца назад

ELSA-2025-23323: python3.12 security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2026-00313

8 месяцев назад

Уязвимость модуля zipfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4487-1

3 месяца назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4398-1

3 месяца назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4389-1

3 месяца назад

Security update for python

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4368-1

3 месяца назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4352-1

4 месяца назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4297-1

4 месяца назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4277-1

4 месяца назад

Security update for python313

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4258-1

4 месяца назад

Security update for python312

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2025-8291

ZIP64 End of Central Directory (EOCD) Locator record offset not checked

CVSS3: 4.3
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-8291

The 'zipfile' module would not check the validity of the ZIP64 End of ...

CVSS3: 4.3
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4313-1

Security update for python

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2025:23940

Moderate: python3.12 security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:23323

Moderate: python3.12 security update

0%
Низкий
3 месяца назад
github логотип
GHSA-49g5-f6qw-8mm7

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2025-23940

ELSA-2025-23940: python3.12 security update (MODERATE)

3 месяца назад
oracle-oval логотип
ELSA-2025-23323

ELSA-2025-23323: python3.12 security update (MODERATE)

3 месяца назад
fstec логотип
BDU:2026-00313

Уязвимость модуля zipfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 4.3
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4487-1

Security update for python36

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4398-1

Security update for python3

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4389-1

Security update for python

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4368-1

Security update for python3

3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4352-1

Security update for python310

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4297-1

Security update for python311

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4277-1

Security update for python313

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4258-1

Security update for python312

4 месяца назад

Уязвимостей на страницу