CVE Published: 03/09/2024 |
CVE Updated: 18/10/2024 |
CVE Year: 2024 Source: PSF |
Vendor: Python Software Foundation |
Product: CPython Status : PUBLISHED
CVE-2024-6232 Description
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.