UBUNTU-CVE-2022-48564
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-48564
UBUNTU-CVE-2022-48564
Summary:
Details: read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
References: https://ubuntu.com/security/CVE-2022-48564, https://github.com/python/cpython/issues/86269, https://github.com/python/cpython/commit/34637a0ce21e7261b952fbd9d006474cc29b681f, https://github.com/python/cpython/commit/e277cb76989958fdbc092bf0b2cb55c43e86610a, https://github.com/python/cpython/commit/225e3659556616ad70186e7efc02baeebfeb5ec4, https://bugs.python.org/issue42103, https://ubuntu.com/security/notices/USN-6513-1, https://www.cve.org/CVERecord?id=CVE-2022-48564, https://ubuntu.com/security/notices/USN-6891-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/python2.7?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
