cbcvebase.
CVE-2024-6232
published 2024-09-03

CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.20%
80.5th percentile
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython2.7< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.11< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.13< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.9< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
msrcazl3_python3_3.12.3-4_on_azure_linux_3.0
msrcazl3_python3_3.12.3-5_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-7_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_python3_3.9.19-13_on_cbl_mariner_2.0
msrccbl2_python3_3.9.19-5_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
pythonpython< 3.8.203.8.20
pythonpython
pythonpython>= 3.10.0 < 3.10.153.10.15
pythonpython>= 3.11.0 < 3.11.103.11.10
pythonpython>= 3.12.0 < 3.12.63.12.6
pythonpython>= 3.9.0 < 3.9.203.9.20
python_software_foundationcpython< 3.8.203.8.20
python_software_foundationcpython>= 3.10.0 < 3.10.153.10.15
python_software_foundationcpython>= 3.11.0 < 3.11.103.11.10
python_software_foundationcpython>= 3.12.0 < 3.12.63.12.6

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.