CVE-2024-6232

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:rc1:*:*:*:*:*:*

History

05 Feb 2025, 19:09

Type Values Removed Values Added
References () https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4 - () https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4 - Patch
References () https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d - () https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d - Patch
References () https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877 - () https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877 - Patch
References () http://www.openwall.com/lists/oss-security/2024/09/03/5 - () http://www.openwall.com/lists/oss-security/2024/09/03/5 - Mailing List, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20241018-0007/ - () https://security.netapp.com/advisory/ntap-20241018-0007/ - Third Party Advisory

31 Jan 2025, 20:15

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4 -

Information

Published : 2024-09-03 13:15

Updated : 2025-03-20 18:15


NVD link : CVE-2024-6232

Mitre link : CVE-2024-6232

CVE.ORG link : CVE-2024-6232


JSON object : View

Products Affected

python

  • python
CWE
CWE-1333

Inefficient Regular Expression Complexity