7.5

CVE-2019-20907

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

Data is provided by the National Vulnerability Database (NVD)
PythonPython Version >= 3.5.0 < 3.5.10
PythonPython Version >= 3.6.0 < 3.6.12
PythonPython Version >= 3.7.0 < 3.7.9
PythonPython Version >= 3.8.0 < 3.8.5
OpensuseLeap Version15.1
OpensuseLeap Version15.2
DebianDebian Linux Version9.0
FedoraprojectFedora Version31
FedoraprojectFedora Version32
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version20.04 SwEditionlts
NetappActive Iq Unified Manager SwPlatformvsphere Version >= 9.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.29% 0.522
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

https://usn.ubuntu.com/4428-1/
Third Party Advisory
https://bugs.python.org/issue39017
Vendor Advisory
Issue Tracking