CVE-2024-0450

SOURCE - nist

Summary

An issue was found in the CPython zipfile module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

EPSS Score: 0.00046 (0.165)

Common Weakness Enumeration (CWE)

SOURCE - nist

Asymmetric Resource Consumption (Amplification)


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/python3.11debdebian12>=3.11.2-6Not yet available
debian/pypy3debdebian10>=7.0.0+dfsg-3Not yet available
debian/pypy3debdebianunstable<7.3.16+dfsg-17.3.16+dfsg-1
debian/pypy3debdebian12>=7.3.11+dfsg-2+deb12u1Not yet available
debian/pypy3debdebian11>=7.3.5+dfsg-2+deb11u2Not yet available
debian/pypy3debdebian13<7.3.16+dfsg-17.3.16+dfsg-1
debian/python2.7debdebian10<2.7.16-2+deb10u42.7.16-2+deb10u4
debian/python2.7debdebian11>=2.7.18-8+deb11u1Not yet available
debian/python3.11debdebian13<3.11.8-13.11.8-1
debian/python3.11debdebianunstable<3.11.8-13.11.8-1
debian/python3.12debdebianunstable<3.12.2-13.12.2-1
debian/python3.12debdebian13<3.12.2-13.12.2-1
debian/python3.7debdebian10<3.7.3-2+deb10u73.7.3-2+deb10u7
debian/python3.9debdebian11>=3.9.2-1Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

2.5


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.2medium

alpine

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

amazon

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

amazon

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

amazon

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

amazon

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

bitnami

CREATED


UPDATED


SOURCE ID

BIT-python-2024-0450


EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

chainguard

CREATED


UPDATED


SOURCE ID

CVE-2024-0450


EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

wolfi

CREATED


UPDATED


SOURCE ID

CVE-2024-0450


EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE