Debian Pypy3 vulnerabilities
62 known vulnerabilities affecting debian/pypy3.
Total CVEs
62
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH19MEDIUM26LOW12
Vulnerabilities
Page 4 of 4
CVE-2019-20907HIGHCVSS 7.5fixed in pypy3 7.3.3+dfsg-1 (bookworm)2019
CVE-2019-20907 [HIGH] CVE-2019-20907: pypy3 - In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR ar...
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Scope: local
bookworm: resolved (fixed in 7.3.3+dfsg-1)
bullseye: resolved (fixed in 7.3.3+dfsg-1)
forky: resolved (fixed in 7.3.3+dfsg-1)
sid: resolved (fixed in 7.3.3+dfsg-1)
trixie:
debian
CVE-2015-20107HIGHCVSS 7.6fixed in pypy3 7.3.11+dfsg-1 (bookworm)2015
CVE-2015-20107 [HIGH] CVE-2015-20107: pypy3 - In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape cha...
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
debian
← Previous4 / 4