ALPINE-CVE-2024-0450

Source
https://security.alpinelinux.org/vuln/CVE-2024-0450
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2024-0450.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2024-0450
Upstream
Published
2024-03-19T16:15:09Z
Modified
2026-08-27T22:18:02Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was found in the CPython zipfile module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

References

Affected packages

Alpine:v3.16 / python3

Package

Name
python3
Purl
pkg:apk/alpine/python3?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.14-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2024-0450.json"

Alpine:v3.17 / python3

Package

Name
python3
Purl
pkg:apk/alpine/python3?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.10.14-r0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2024-0450.json"