Back

HIGH

python: infinite loop in the tarfile module via crafted TAR archive

Published Jul 13, 2020

Description

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

Affected products

Remediation

Red Hat statement

A service is vulnerable if it uses python's tarfile module to open untrusted tar files. If an attacker is able to submit a crafted tar file to a service which uses the tarfile module to open it, an infinite loop will be executed, potentially causing a denial of service. The tarfile module is included with python. Versions of `python36:3.6/python36` as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main `python3` component, which provides the actual interpreter of the Python programming language.

Red Hat mitigation

This flaw can be mitigated by not opening untrusted files with tarfile.

Metrics

Weaknesses (1)

References (31)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 13, 2020
Updated Aug 5, 2024
Reserved Jul 13, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 10, 2019