CVE-2019-9674
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb. (CVE-2019-9674)
highEPSS 5.5%
Description
Metrics
Severity
high
92.89
no public PoC known
7.5
92.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2020-02-04 14:05 UTC
—
Affected operating systems
linux
canonical / ubuntu_linux12.04
linux
canonical / ubuntu_linux14.04
linux
canonical / ubuntu_linux16.04
linux
canonical / ubuntu_linux18.04
linux
canonical / ubuntu_linux20.04
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
netapp
active_iq_unified_manager
python
python3.2 – 3.8
References & sources
- https://www.python.org/news/security/x_refsource_MISC
- https://github.com/python/cpython/blob/master/Lib/zipfile.pyx_refsource_MISC
- https://bugs.python.org/issue36462x_refsource_MISC
- https://bugs.python.org/issue36260x_refsource_MISC
- https://python-security.readthedocs.io/security.html#archives-and-zip-bombx_refsource_MISC
- https://security.netapp.com/advisory/ntap-20200221-0003/x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00041.htmlvendor-advisoryx_refsource_SUSE
- https://usn.ubuntu.com/4428-1/vendor-advisoryx_refsource_UBUNTU
IDCVE-2019-9674