Lack of data validation In python3
Description
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.19 | 3.8.5-r0 | ||
alpine v3.16 | 3.8.5-r0 | ||
alpine v3.18 | 3.8.5-r0 | ||
alpine v3.12 | 3.8.5-r0 | ||
alpine v3.13 | 3.8.5-r0 | ||
alpine v3.14 | 3.8.5-r0 | ||
alpine v3.15 | 3.8.5-r0 | ||
alpine v3.17 | 3.8.5-r0 | ||
alpine v3.20 | 3.8.5-r0 | ||
alpine v3.21 | 3.8.5-r0 |
1-10 of 25
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17.