Lack of data validation - Path Traversal In python3
Description
An issue was found in the CPython zipfile module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 7.3.16+dfsg-1 | ||
debian 12 | 3.11.2-6+deb12u2 | ||
rpm rhel8 | 0:3.11.9-1.el8_10 | ||
rpm rhel8 | 0:3.12.3-2.el8_10 | ||
rpm rhel9 | 0:3.12.5-2.el9 | ||
rpm rhel9 | 0:3.11.9-7.el9 | ||
alpine v3.16 | 3.10.14-r0 | ||
alpine v3.17 | 3.10.14-r0 | ||
debian 12 | 7.3.11+dfsg-2+deb12u2 | ||
debian 14 | 7.3.16+dfsg-1 |
1-10 of 18
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.