CVE-2024-6232
03.09.2024, 13:15
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.Enginsight
Vendor | Product | Version |
---|---|---|
python | python | 𝑥 < 3.8.20 |
python | python | 3.9.0 ≤ 𝑥 < 3.9.20 |
python | python | 3.10.0 ≤ 𝑥 < 3.10.15 |
python | python | 3.11.0 ≤ 𝑥 < 3.11.10 |
python | python | 3.12.0 ≤ 𝑥 < 3.12.6 |
python | python | 3.13.0:alpha0 |
python | python | 3.13.0:alpha1 |
python | python | 3.13.0:alpha2 |
python | python | 3.13.0:alpha3 |
python | python | 3.13.0:alpha4 |
python | python | 3.13.0:alpha5 |
python | python | 3.13.0:alpha6 |
python | python | 3.13.0:beta1 |
python | python | 3.13.0:beta2 |
python | python | 3.13.0:beta3 |
python | python | 3.13.0:beta4 |
python | python | 3.13.0:rc1 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||
---|---|---|---|---|---|---|---|
python2.7 |
| ||||||
python3.11 |
| ||||||
python3.12 |
| ||||||
python3.13 |
| ||||||
python3.9 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||
python3.10 |
| ||||||||||||||||
python3.11 |
| ||||||||||||||||
python3.12 |
| ||||||||||||||||
python3.13 |
| ||||||||||||||||
python3.4 |
| ||||||||||||||||
python3.5 |
| ||||||||||||||||
python3.6 |
| ||||||||||||||||
python3.7 |
| ||||||||||||||||
python3.8 |
| ||||||||||||||||
python3.9 |
|
Common Weakness Enumeration
References