Schwachstellenklasse
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
Quellen
- https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8
- https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89
- https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70
- https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a
- https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de
- https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.