There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is unaffected. When iterating over names of entries in a zip archive (for example, methods of "zipfile.Path" like "namelist()", "iterdir()", etc) the process can be put into an infinite loop with a maliciously crafted zip archive. This defect applies when reading only metadata or extracting the contents of the zip archive. Programs that are not handling user-controlled zip archives are not affected.
{ "binaries": [ { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "idle-python3.8" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8-dbg" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8-dev" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8-minimal" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8-stdlib" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "libpython3.8-testsuite" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-dbg" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-dev" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-doc" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-examples" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-full" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-minimal" }, { "binary_version": "3.8.10-0ubuntu1~20.04.12", "binary_name": "python3.8-venv" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "3.10.12-1~22.04.6", "binary_name": "idle-python3.10" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10-dbg" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10-dev" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10-minimal" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10-stdlib" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "libpython3.10-testsuite" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-dbg" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-dev" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-doc" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-examples" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-full" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-minimal" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-nopie" }, { "binary_version": "3.10.12-1~22.04.6", "binary_name": "python3.10-venv" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "idle-python3.12" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12-dev" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12-minimal" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12-stdlib" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12-testsuite" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12t64" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "libpython3.12t64-dbg" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-dbg" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-dev" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-doc" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-examples" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-full" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-minimal" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-nopie" }, { "binary_version": "3.12.3-1ubuntu0.2", "binary_name": "python3.12-venv" } ], "availability": "No subscription required" }