发布时间: 2024年7月26日
修改时间: 2024年8月19日
A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the `Path` module in both zipp and zipfile, such as `joinpath`, the overloaded division operator, and `iterdir`. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.
NVD | openEuler | |
---|---|---|
Confidentiality | None | |
Attack Vector | Local | |
CVSS评分 | N/A | 6.2 |
Attack Complexity | Low | |
Privileges Required | None | |
Scope | Unchanged | |
Integrity | None | |
User Interaction | None | |
Availability | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-3229 | python-zipp security update | 2024年7月26日 |
KylinSec-SA-2024-4810 | python-zipp security update | 2025年2月17日 |
产品 | 包 | 状态 |
---|---|---|
KY3.5.2 | python-zipp | Fixed |
V6 | python-zipp | Fixed |
KY3.5.3 | python-zipp | Fixed |