CVE-2024-0450
published 2024-03-19CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable…
PriorityP425medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.34%
25.8th percentile
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) |
| debian | python2.7 | < pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) |
| debian | python3.11 | < pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) |
| debian | python3.9 | < pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) | pypy3 7.3.11+dfsg-2+deb12u2 (bookworm) |
| msrc | azl3_python3_3.12.0-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python3_3.9.14-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| python_software_foundation | cpython | < 3.8.19 | 3.8.19 |
| python_software_foundation | cpython | >= 3.10.0 < 3.10.14 | 3.10.14 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.8 | 3.11.8 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.2 | 3.12.2 |
| python_software_foundation | cpython | >= 3.13.0a1 < 3.13.0a3 | 3.13.0a3 |
| python_software_foundation | cpython | >= 3.9.0 < 3.9.19 | 3.9.19 |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian6.2MEDIUM
vendor_msrc6.2MEDIUM
vendor_oracle6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python2.7 vulnerabilities
osv·2025-01-16·CVSS 7.5
CVE-2019-9674 [HIGH] python2.7 vulnerabilities
python2.7 vulnerabilities
It was discovered that Python incorrectly handled certain ZIP files. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 22.04 LTS. (CVE-2019-9674)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were tricked into running a specially
crafted input, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-45061)
It was discovered that Python incorrectly handled certain crafted ZIP
files. An attacker could possibly use this issue to crash the program,
resulting in a denial of service. (CVE-2024-0450)
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-jm46-725r-hh9v: An issue was found in the CPython `zipfile` module affecting versions 3
ghsa_unreviewed·2024-03-19
CVE-2024-0450 [MEDIUM] CWE-405 GHSA-jm46-725r-hh9v: An issue was found in the CPython `zipfile` module affecting versions 3
An issue was found in the CPython `zipfile` module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
OSV
CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3
osv·2024-03-19·CVSS 6.2
CVE-2024-0450 [MEDIUM] CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
OSV
CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3
osv·2024-03-19·CVSS 6.2
CVE-2024-0450 [MEDIUM] CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Ubuntu
Python 2.7 vulnerabilities
vendor_ubuntu·2025-01-16·CVSS 7.5
CVE-2022-45061 [HIGH] Python 2.7 vulnerabilities
Title: Python 2.7 vulnerabilities
Summary: Several security issues were fixed in Python 2.7.
It was discovered that Python incorrectly handled certain ZIP files. An
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 22.04 LTS. (CVE-2019-9674)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were tricked into running a specially
crafted input, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-45061)
It was discovered that Python incorrectly handled certain crafted ZIP
files. An attacker could possibly use this issue to crash the program,
resulting in a denial of service. (CVE-2024-0450)
Instructions: In general, a standard system update will make all
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite (Python) — CVE-2024-0450
vendor_oracle·2025-01-15·CVSS 6.2
CVE-2024-0450 [MEDIUM] Oracle Oracle Communications Risk Matrix: Automated Test Suite (Python) — CVE-2024-0450
Oracle Oracle Communications Risk Matrix: Automated Test Suite (Python) vulnerability
CVE: CVE-2024-0450
CVSS: 6.2
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Python) — CVE-2024-0450
vendor_oracle·2024-10-15·CVSS 6.2
CVE-2024-0450 [MEDIUM] Oracle Oracle Communications Risk Matrix: Configuration (Python) — CVE-2024-0450
Oracle Oracle Communications Risk Matrix: Configuration (Python) vulnerability
CVE: CVE-2024-0450
CVSS: 6.2
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Python) — CVE-2024-0450
vendor_oracle·2024-07-15·CVSS 6.2
CVE-2024-0450 [MEDIUM] Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Python) — CVE-2024-0450
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (Python) vulnerability
CVE: CVE-2024-0450
CVSS: 6.2
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2024 (JUL 2024)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Red Hat
python: The zipfile module is vulnerable to zip-bombs leading to denial of service
vendor_redhat·2024-03-19·CVSS 6.2
CVE-2024-0450 [MEDIUM] CWE-450 python: The zipfile module is vulnerable to zip-bombs leading to denial of service
python: The zipfile module is vulnerable to zip-bombs leading to denial of service
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.
The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
A flaw was found in the Python/CPython 'zipfile' that can allow a zip-bomb type of attack. An attacker may craft a zip file format, leading to a Denial of Service when processed.
Statement: Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to t
Microsoft
Quoted zip-bomb protection for zipfile
vendor_msrc·2024-03-12·CVSS 6.2
CVE-2024-0450 [MEDIUM] CWE-405 Quoted zip-bomb protection for zipfile
Quoted zip-bomb protection for zipfile
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/
Debian
CVE-2024-0450: pypy3 - An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3....
vendor_debian·2024·CVSS 6.2
CVE-2024-0450 [MEDIUM] CVE-2024-0450: pypy3 - An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3....
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.
Scope: local
bookworm: resolved (fixed in 7.3.11+dfsg-2+deb12u2)
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u3)
forky: resolved (fixed in 7.3.16+dfsg-1)
sid: resolved (fixed in 7.3.16+dfsg-1)
trixie: resolved (fixed in 7.3.16+dfsg-1)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/03/20/5https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85https://github.com/python/cpython/commit/66363b9a7b9fe7c99eba3a185b74c5fdbf842ebahttps://github.com/python/cpython/commit/70497218351ba44bffc8b571201ecb5652d84675https://github.com/python/cpython/commit/a2c59992e9e8d35baba9695eb186ad6c6ff85c51https://github.com/python/cpython/commit/a956e510f6336d5ae111ba429a61c3ade30a7549https://github.com/python/cpython/commit/d05bac0b74153beb541b88b4fca33bf053990183https://github.com/python/cpython/commit/fa181fcf2156f703347b03a3b1966ce47be8ab3bhttps://github.com/python/cpython/issues/109858https://lists.debian.org/debian-lts-announce/2024/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2024/03/msg00025.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/https://lists.fedoraproject.org/archives/list/[email protected]/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/https://mail.python.org/archives/list/[email protected]/thread/XELNUX2L3IOHBTFU7RQHCY6OUVEWZ2FG/https://www.bamsoftware.com/hacks/zipbomb/http://www.openwall.com/lists/oss-security/2024/03/20/5https://github.com/python/cpython/commit/30fe5d853b56138dbec62432d370a1f99409fc85https://github.com/python/cpython/commit/66363b9a7b9fe7c99eba3a185b74c5fdbf842ebahttps://github.com/python/cpython/commit/70497218351ba44bffc8b571201ecb5652d84675https://github.com/python/cpython/commit/a2c59992e9e8d35baba9695eb186ad6c6ff85c51https://github.com/python/cpython/commit/a956e510f6336d5ae111ba429a61c3ade30a7549https://github.com/python/cpython/commit/d05bac0b74153beb541b88b4fca33bf053990183https://github.com/python/cpython/commit/fa181fcf2156f703347b03a3b1966ce47be8ab3bhttps://github.com/python/cpython/issues/109858https://lists.debian.org/debian-lts-announce/2024/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2024/03/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2024/11/msg00005.htmlhttps://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/https://lists.fedoraproject.org/archives/list/[email protected]/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/https://mail.python.org/archives/list/[email protected]/thread/XELNUX2L3IOHBTFU7RQHCY6OUVEWZ2FG/https://security.netapp.com/advisory/ntap-20250411-0005/https://www.bamsoftware.com/hacks/zipbomb/
2024-03-19
Published