UBUNTU-CVE-2024-6232
Dashboard / Vulnerabilities / UBUNTU-CVE-2024-6232
UBUNTU-CVE-2024-6232
Summary:
Details: There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
References: https://ubuntu.com/security/CVE-2024-6232, https://www.cve.org/CVERecord?id=CVE-2024-6232, https://github.com/python/cpython/pull/121286, https://mail.python.org/archives/list/[email protected]/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/, https://ubuntu.com/security/notices/USN-7015-1, https://ubuntu.com/security/notices/USN-7015-2, https://ubuntu.com/security/notices/USN-7015-5, https://ubuntu.com/security/notices/USN-7488-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/[email protected]+esm21?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
