Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <b330440a-3d8b-4452-8cfc-20d95925ec3d@oracle.com>
Date: Tue, 3 Sep 2024 10:35:35 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: CPython: [CVE-2024-6232] Regular-expression DoS when parsing TarFile
 headers

The CVE record currently says:
  Versions: affected from 0 before 3.13.0rc2

and points to https://github.com/python/cpython/issues/121285 which provides
this slightly expanded description:

"Today the tarfile module parsing of header values allows for backtracking
  when parsing header values. Headers have a well-known format that doesn't
  require backtracking to parse reliably, the new method of parsing will only
  require a single pass over a byte stream."

and has links to pull requests for Python versions 3.8 through 3.13.

-------- Forwarded Message --------
Subject: 	[Security-announce][CVE-2024-6232] Regular-expression DoS when parsing 
TarFile headers
Date: 	Tue, 3 Sep 2024 07:30:02 -0500
From: 	Seth Larson <seth@...hon.org>
Reply-To: 	security-sig@...hon.org
To: 	security-announce@...hon.org



There is a MEDIUM severity vulnerability affecting CPython.

Regular expressions that allowed excessive backtracking during tarfile.TarFile 
header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

Please see the linked CVE ID for the latest information on affected versions:

* https://www.cve.org/CVERecord?id=CVE-2024-6232
* https://github.com/python/cpython/pull/121286

_______________________________________________
Security-announce mailing list -- security-announce@...hon.org
https://mail.python.org/mailman3/lists/security-announce.python.org/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.