CVE-2019-20907
published 2020-07-13CVE-2019-20907: In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.04%
92.6th percentile
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | pypy3 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| debian | python2.7 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| debian | python3.9 | < pypy3 7.3.3+dfsg-1 (bookworm) | pypy3 7.3.3+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python2_2.7.18-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python2_2.7.18-5_on_cbl_mariner_1.0 | — | — |
| msrc | cm1_python3_3.7.10-3_on_cbl_mariner_1.0 | — | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| python | python | >= 3.5.0 < 3.5.10 | 3.5.10 |
| python | python | >= 3.6.0 < 3.6.12 | 3.6.12 |
| python | python | >= 3.7.0 < 3.7.9 | 3.7.9 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-xc97-8p9q-cf27: In Lib/tarfile
ghsa_unreviewed·2022-05-24
CVE-2019-20907 [MEDIUM] CWE-20 GHSA-xc97-8p9q-cf27: In Lib/tarfile
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
OSV
python2.7, python3.7, python3.8 vulnerabilities
osv·2021-03-12·CVSS 7.5
CVE-2019-9674 [HIGH] python2.7, python3.7, python3.8 vulnerabilities
python2.7, python3.7, python3.8 vulnerabilities
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python allowed an HTTP server to conduct Regular
Expression Den
OSV
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
osv·2020-07-22·CVSS 7.5
CVE-2019-17514 [HIGH] python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
It was discovered that Python documentation had a misleading information.
A security issue could be possibly caused by wrong assumptions of this information.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that incorrectly handled certain ZIP files. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-9674)
It was discovered that Python incorrectl
OSV
CVE-2019-20907: In Lib/tarfile
osv·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907: In Lib/tarfile
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-03-12·CVSS 7.5
CVE-2020-8492 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python 2.7 and Python 3.8.
USN-4754-1 fixed vulnerabilities in Python. This update provides
the corresponding updates for Ubuntu 18.04 and Ubuntu 20.04.
In the case of Python 2.7 for 20.04, these additional fixes are included:
It was dicovered that Python allowed remote attackers to cause a denial of
service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
It was discovered that Python had potentially misleading information about
whether sorting occurs. This fix updates the documentation about it.
(CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that Python
Ubuntu
Python vulnerabilities
vendor_ubuntu·2020-07-22·CVSS 7.5
CVE-2019-20907 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python documentation had a misleading information.
A security issue could be possibly caused by wrong assumptions of this information.
This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-17514)
It was discovered that Python incorrectly handled certain TAR archives.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2019-20907)
It was discovered that incorrectly handled certain ZIP files. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-9674)
It was discovered that P
Microsoft
In Lib/tarfile.py in Python through 3.8.3 an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open because _proc_pax lacks header validation.
vendor_msrc·2020-07-14·CVSS 7.5
CVE-2019-20907 [HIGH] CWE-835 In Lib/tarfile.py in Python through 3.8.3 an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open because _proc_pax lacks header validation.
In Lib/tarfile.py in Python through 3.8.3 an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open because _proc_pax lacks header validation.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect t
Red Hat
python: infinite loop in the tarfile module via crafted TAR archive
vendor_redhat·2019-12-10·CVSS 7.5
CVE-2019-20907 [HIGH] CWE-835 python: infinite loop in the tarfile module via crafted TAR archive
python: infinite loop in the tarfile module via crafted TAR archive
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
A flaw was found in python. In Lib/tarfile.py an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Statement: A service is vulnerable if it uses python's tarfile module to open untrusted tar files. If an attacker is able to submit a crafted tar file to a service which uses the tarfile module to open it, an infinite loop will be executed, potentially causing a denial of service. The tarfile module is included with python.
Versions of `python36:3.6/py
Debian
CVE-2019-20907: pypy3 - In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR ar...
vendor_debian·2019·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907: pypy3 - In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR ar...
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Scope: local
bookworm: resolved (fixed in 7.3.3+dfsg-1)
bullseye: resolved (fixed in 7.3.3+dfsg-1)
forky: resolved (fixed in 7.3.3+dfsg-1)
sid: resolved (fixed in 7.3.3+dfsg-1)
trixie: resolved (fixed in 7.3.3+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-20907 python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python38: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python38: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python38: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python39: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python39: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python39: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python34: python: infinite loop in the tarfile module via crafted TAR archive [epel-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python34: python: infinite loop in the tarfile module via crafted TAR archive [epel-all]
CVE-2019-20907 python34: python: infinite loop in the tarfile module via crafted TAR archive [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2019-20907 python34: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python34: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
CVE-2019-20907 python34: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python35: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python35: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python35: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python37: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python37: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python37: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python26: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python26: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
CVE-2019-20907 python26: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python36: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python36: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python36: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 mingw-python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 mingw-python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 mingw-python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
Bugzilla
CVE-2019-20907 python2: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python2: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
CVE-2019-20907 python2: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-20907 python: infinite loop in the tarfile module via crafted TAR archive
bugzilla·2020-07-13·CVSS 7.5
CVE-2019-20907 [HIGH] CVE-2019-20907 python: infinite loop in the tarfile module via crafted TAR archive
CVE-2019-20907 python: infinite loop in the tarfile module via crafted TAR archive
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Reference:
https://bugs.python.org/issue39017
Upstream commit:
https://github.com/python/cpython/pull/21454
Discussion:
Created mingw-python3 tracking bugs for this issue:
Affects: fedora-all [bug 1856489]
Created python2 tracking bugs for this issue:
Affects: fedora-all [bug 1856485]
Created python26 tracking bugs for this issue:
Affects: fedora-all [bug 1856486]
Created python3 tracking bugs for this issue:
Affects: fedora-all [bug 1856488]
Created python34 tracking bugs for this issue:
Affects: epel-all [
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.htmlhttps://bugs.python.org/issue39017https://github.com/python/cpython/pull/21454https://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2020/11/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/https://security.gentoo.org/glsa/202008-01https://security.netapp.com/advisory/ntap-20200731-0002/https://usn.ubuntu.com/4428-1/https://www.oracle.com/security-alerts/cpujan2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.htmlhttps://bugs.python.org/issue39017https://github.com/python/cpython/pull/21454https://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2020/11/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/https://security.gentoo.org/glsa/202008-01https://security.netapp.com/advisory/ntap-20200731-0002/https://usn.ubuntu.com/4428-1/https://www.oracle.com/security-alerts/cpujan2021.html
2020-07-13
Published