REDHAT-BUG-2309426: Medium severity cpython vulnerability
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2309426?
The severity of REDHAT-BUG-2309426 is classified as MEDIUM.
How does REDHAT-BUG-2309426 affect CPython?
REDHAT-BUG-2309426 affects CPython by allowing ReDoS attacks through excessive backtracking in regular expressions during tarfile header parsing.
What is a ReDoS attack in the context of REDHAT-BUG-2309426?
A ReDoS attack, in the context of REDHAT-BUG-2309426, involves exploiting the excessive backtracking of regular expressions to degrade the performance of the application.
How can I mitigate the risks associated with REDHAT-BUG-2309426?
To mitigate the risks associated with REDHAT-BUG-2309426, ensure that you are using the latest security patches and validate tar archives before processing.
Is there a specific version of CPython affected by REDHAT-BUG-2309426?
While specific versions are not mentioned, CPython versions susceptible to excessive backtracking in tarfile processing are affected by REDHAT-BUG-2309426.