cbcvebase.
CVE-2024-0450
published 2024-03-19

CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable…

PriorityP425medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.34%
25.8th percentile
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)
debianpython2.7< pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)
debianpython3.11< pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)
debianpython3.9< pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)
msrcazl3_python3_3.12.0-4_on_azure_linux_3.0
msrcazl3_python3_3.12.3-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_python3_3.9.14-8_on_cbl_mariner_2.0
msrccbl2_python3_3.9.19-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
python_software_foundationcpython< 3.8.193.8.19
python_software_foundationcpython>= 3.10.0 < 3.10.143.10.14
python_software_foundationcpython>= 3.11.0 < 3.11.83.11.8
python_software_foundationcpython>= 3.12.0 < 3.12.23.12.2
python_software_foundationcpython>= 3.13.0a1 < 3.13.0a33.13.0a3
python_software_foundationcpython>= 3.9.0 < 3.9.193.9.19

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian6.2MEDIUM
vendor_msrc6.2MEDIUM
vendor_oracle6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.