Intel

CVE-2024-6232

Python is vulnerable to ReDoS

ReDoS Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

75

High Risk

This Affects:

Python

TL;DR

There is a ReDoS vulnerability affecting Python. This could be triggered by having Python open specifically crafted Tar archives.

Who does this affect?

You're running any version of 'Python' up to 3.12.5

Background info

Python is vulnerable to ReDoS in versions < 3.8.20, < 3.9.20, < 3.10.15, < 3.11.10 and < 3.12.6.

How to fix this

Upgrade Python library to patch version.

Links

Fix Commits