CVE-2019-9674
🟡 Monitoruj
Wykorzystanie ZIP bomba w lib/zipfile.py w Pythonie prowadzi do odmowy usługi.
CVSS
7.5
EPSS
5.5%
Exploit
none
Vendor
canonical
Opis źródłowy (NVD)
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.5% |
| Opublikowano (NVD) | 2020-02-04 15:15:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:20 UTC |
Referencje
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html ([email protected]) [Broken Link]
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.html ([email protected]) [Broken Link]
- https://bugs.python.org/issue36260 ([email protected]) [Issue Tracking, Vendor Advisory]
- https://bugs.python.org/issue36462 ([email protected]) [Issue Tracking, Vendor Advisory]
- https://github.com/python/cpython/blob/master/Lib/zipfile.py ([email protected]) [Third Party Advisory]
- https://python-security.readthedocs.io/security.html#archives-and-zip-bomb ([email protected]) [Vendor Advisory]
- https://security.netapp.com/advisory/ntap-20200221-0003/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/4428-1/ ([email protected]) [Third Party Advisory]
- https://www.python.org/news/security/ ([email protected]) [Vendor Advisory]