[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1483 --- python

ID: oval:org.secpod.oval:def:1700394Date: (C)2020-09-15   (M)2023-12-20
Class: PATCHFamily: unix




In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation

Platform:
Amazon Linux 2
Product:
python
Reference:
ALAS2-2020-1483
CVE-2019-20907
CVE    1
CVE-2019-20907

© SecPod Technologies