CVE-2024-8088 Affecting python3.12-debug package, versions <0:3.12.5-2.el9
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ALMALINUX9-PYTHON312DEBUG-8383973
- published 19 Nov 2024
- disclosed 12 Nov 2024
How to fix?
Upgrade AlmaLinux:9
python3.12-debug
to version 0:3.12.5-2.el9 or higher.
This issue was patched in ALSA-2024:9190
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream python3.12-debug
package and not the python3.12-debug
package as distributed by AlmaLinux
.
See How to fix?
for AlmaLinux:9
relevant fixed versions and status.
There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected.
When iterating over names of entries in a zip archive (for example, methods of "zipfile.Path" like "namelist()", "iterdir()", etc) the process can be put into an infinite loop with a maliciously crafted zip archive. This defect applies when reading only metadata or extracting the contents of the zip archive. Programs that are not handling user-controlled zip archives are not affected.
References
- https://errata.almalinux.org/8/ALSA-2024-5962.html
- https://errata.almalinux.org/8/ALSA-2024-6961.html
- https://errata.almalinux.org/8/ALSA-2024-6962.html
- https://errata.almalinux.org/9/ALSA-2024-9190.html
- https://errata.almalinux.org/9/ALSA-2024-9192.html
- https://errata.almalinux.org/9/ALSA-2024-9371.html
- https://access.redhat.com/security/cve/CVE-2024-8088
- https://access.redhat.com/errata/RHSA-2024:5962
- https://access.redhat.com/errata/RHSA-2024:6961
- https://access.redhat.com/errata/RHSA-2024:6962
- https://access.redhat.com/errata/RHSA-2024:9190
- https://access.redhat.com/errata/RHSA-2024:9192
- https://access.redhat.com/errata/RHSA-2024:9371
- https://github.com/python/cpython/commit/795f2597a4be988e2bb19b69ff9958e981cb894e
- https://github.com/python/cpython/commit/8c7348939d8a3ecd79d630075f6be1b0c5b41f64
- https://github.com/python/cpython/commit/dcc5182f27c1500006a1ef78e10613bb45788dea
- https://github.com/python/cpython/issues/122905
- https://github.com/python/cpython/pull/122906
- https://mail.python.org/archives/list/security-announce@python.org/thread/GNFCKVI4TCATKQLALJ5SN4L4CSPSMILU/
- https://github.com/python/cpython/commit/e0264a61119d551658d9445af38323ba94fc16db
- https://github.com/python/cpython/issues/123270
- https://github.com/python/cpython/commit/2231286d78d328c2f575e0b05b16fe447d1656d6
- https://github.com/python/cpython/commit/7e8883a3f04d308302361aeffc73e0e9837f19d4
- https://github.com/python/cpython/commit/95b073bddefa6243effa08e131e297c0383e7f6a
- https://github.com/python/cpython/commit/7bc367e464ce50b956dd232c1dfa1cad4e7fb814
- https://github.com/python/cpython/commit/962055268ed4f2ca1d717bfc8b6385de50a23ab7
- https://github.com/python/cpython/commit/fc0b8259e693caa8400fa8b6ac1e494e47ea7798
- https://github.com/python/cpython/commit/0aa1ee22ab6e204e9d3d0e9dd63ea648ed691ef1
- http://www.openwall.com/lists/oss-security/2024/08/22/1
- http://www.openwall.com/lists/oss-security/2024/08/22/4
- http://www.openwall.com/lists/oss-security/2024/08/23/1
- http://www.openwall.com/lists/oss-security/2024/08/23/2
- https://security.netapp.com/advisory/ntap-20241011-0010/