First published: Thu Nov 21 2024(Updated: )
A pathlib-compatible Zipfile object wrapper. A backport of the Path object.<br>Security Fix(es):<br><li> Denial of Service (infinite loop) via crafted zip file in jaraco/zipp</li> (CVE-2024-5569)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-zipp | <3.4.0-3.el9 | 3.4.0-3.el9 |
redhat/python3-zipp | <3.4.0-3.el9 | 3.4.0-3.el9 |
Red Hat Enterprise Linux 8 | ||
Red Hat OpenStack Director Deployment Tools | ||
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:9977 is classified as moderate.
To fix RHSA-2024:9977, update the python-zipp or python3-zipp package to version 3.4.0-3.el9.
RHSA-2024:9977 addresses a Denial of Service vulnerability through an infinite loop caused by a crafted zip file.
RHSA-2024:9977 affects Red Hat Enterprise Linux for x86_64, Red Hat OpenStack Director Deployment Tools, and Red Hat OpenStack.
RHSA-2024:9977 reports the CVE-2024-5569 related to a Denial of Service vulnerability.