Back

HIGH

python: Nested zip file (Zip bomb) vulnerability in Lib/zipfile.py

Published Feb 4, 2020

Description

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

Affected products

Remediation

Red Hat statement

There is no plan to fix this flaw. Programs using the Python zipfile module should be responsible for validating external untrusted ZIP files. For further details, please refer to the following URLs: [1] https://docs.python.org/dev/library/zipfile.html#decompression-pitfalls [2] https://python-security.readthedocs.io/security.html#archives-and-zip-bomb

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 4, 2020
Updated Aug 4, 2024
Reserved Mar 11, 2019
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 11, 2019