UBUNTU-CVE-2019-9674
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9674
UBUNTU-CVE-2019-9674
Summary:
Details: Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
References: https://ubuntu.com/security/CVE-2019-9674, https://github.com/python/cpython/blob/master/Lib/zipfile.py, https://python-security.readthedocs.io/security.html#archives-and-zip-bomb, https://www.python.org/news/security/, https://ubuntu.com/security/notices/USN-4428-1, https://ubuntu.com/security/notices/USN-4754-3, https://www.cve.org/CVERecord?id=CVE-2019-9674, https://ubuntu.com/security/notices/USN-6891-1, https://ubuntu.com/security/notices/USN-7212-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/[email protected]+esm6?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
