CVE-2024-0450

An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Configurations

No configuration.

History

07 May 2024, 22:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/70497218351ba44bffc8b571201ecb5652d84675 -

01 May 2024, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/20/5 -

03 Apr 2024, 15:15

Type Values Removed Values Added
Summary (en) An issue was found in the CPython `zipfile` module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive. (en) An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

24 Mar 2024, 23:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00024.html -
  • () https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html -
Summary
  • (es) Se encontró un problema en el módulo `zipfile` de CPython que afecta a las versiones 3.12.2, 3.11.8, 3.10.13, 3.9.18 y 3.8.18 y anteriores. El módulo zipfile es vulnerable a bombas zip "superpuestas entre comillas" que explotan el formato zip para crear una bomba zip con una alta relación de compresión. Las versiones fijas de CPython hacen que el módulo zipfile rechace archivos zip que se superponen con entradas en el archivo.

19 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-19 16:15

Updated : 2024-05-07 22:15


NVD link : CVE-2024-0450

Mitre link : CVE-2024-0450

CVE.ORG link : CVE-2024-0450


JSON object : View

Products Affected

No product.

CWE
CWE-405

Asymmetric Resource Consumption (Amplification)