In Lib/tarfile.py in Python through 3.8.3, an attacker is...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 24, 2023
Description
Published by the National Vulnerability Database
Jul 13, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 24, 2023
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
References