7.5

CVE-2024-6232

Exploit

Regular-expression DoS when parsing TarFile headers

There is a MEDIUM severity vulnerability affecting CPython.





Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version < 3.8.20
Python ≫ Python Version >= 3.9.0 < 3.9.20
Python ≫ Python Version >= 3.10.0 < 3.10.15
Python ≫ Python Version >= 3.11.0 < 3.11.10
Python ≫ Python Version >= 3.12.0 < 3.12.6
Python ≫ Python Version 3.13.0 Update alpha0
Python ≫ Python Version 3.13.0 Update alpha1
Python ≫ Python Version 3.13.0 Update alpha2
Python ≫ Python Version 3.13.0 Update alpha3
Python ≫ Python Version 3.13.0 Update alpha4
Python ≫ Python Version 3.13.0 Update alpha5
Python ≫ Python Version 3.13.0 Update alpha6
Python ≫ Python Version 3.13.0 Update beta1
Python ≫ Python Version 3.13.0 Update beta2
Python ≫ Python Version 3.13.0 Update beta3
Python ≫ Python Version 3.13.0 Update beta4
Python ≫ Python Version 3.13.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.2% 0.802
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-1333 Inefficient Regular Expression Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4
Patch
https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06
Patch
https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4
Patch
https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d
Patch
https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877
Patch
https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf
Patch
https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373
Patch
https://github.com/python/cpython/issues/121285
Patch
Exploit
Issue Tracking
https://github.com/python/cpython/pull/121286
Patch
Issue Tracking
https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/
Vendor Advisory
http://www.openwall.com/lists/oss-security/2024/09/03/5
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20241018-0007/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html