Asymmetric denial of service - ReDoS In pypy3
Description
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.21 | 3.12.6-r0 | ||
alpine v3.17 | 3.10.15-r0 | ||
alpine v3.18 | 3.11.10-r0 | ||
alpine v3.19 | 3.11.10-r0 | ||
alpine v3.20 | 3.12.6-r0 | ||
alpine v3.22 | 3.12.6-r0 | ||
debian 12 | - | ||
debian 13 | 7.3.18+dfsg-1 | ||
debian 14 | 7.3.18+dfsg-1 | ||
debian 12 | 3.11.2-6+deb12u4 |
1-10 of 30
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.