CVE-2024-0450
19.03.2024, 16:15
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to quoted-overlap zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Awaiting analysis
This vulnerability is currently awaiting analysis.

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
pypy3 |
| ||||||||||
python2.7 |
| ||||||||||
python3.11 |
| ||||||||||
python3.12 |
| ||||||||||
python3.9 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||||
python3.10 |
| ||||||||||||||||||
python3.11 |
| ||||||||||||||||||
python3.12 |
| ||||||||||||||||||
python3.4 |
| ||||||||||||||||||
python3.5 |
| ||||||||||||||||||
python3.6 |
| ||||||||||||||||||
python3.7 |
| ||||||||||||||||||
python3.8 |
| ||||||||||||||||||
python3.9 |
|
Common Weakness Enumeration
References