CVE-2023-41105
23.08.2023, 07:15
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | python | 3.11.0 ≤ 𝑥 ≤ 3.11.4 |
| netapp | active_iq_unified_manager | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python |
| ||||||||||||||||||
| python2.7 |
| ||||||||||||||||||
| python3.10 |
| ||||||||||||||||||
| python3.11 |
| ||||||||||||||||||
| python3.12 |
| ||||||||||||||||||
| python3.4 |
| ||||||||||||||||||
| python3.5 |
| ||||||||||||||||||
| python3.6 |
| ||||||||||||||||||
| python3.7 |
| ||||||||||||||||||
| python3.8 |
| ||||||||||||||||||
| python3.9 |
|
Common Weakness Enumeration
References