CVE-2024-6232
Vulnerability Summary
Timeline
Description
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 2.20%• Percentile: 82%
Techniques & Countermeasures
- CWE-1333•Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
Affected Systems
- alpine•python3
< 3.10.15-r0 | < 3.11.10-r0 | < 3.11.10-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0
- chainguard•python-3.10
< 3.10.15-r0
- chainguard•python-3.11
< 3.11.9-r9
- chainguard•python-3.12
< 3.12.5-r3
- chainguard•python-3.13
< 3.13.2-r6
- chainguard•python-3.9
< 3.9.20-r0
- wolfi•python-3.10
< 3.10.15-r0
- wolfi•python-3.11
< 3.11.9-r9
- wolfi•python-3.12
< 3.12.5-r3
- wolfi•python-3.13
< 3.13.2-r6
- debian•pypy3
< 7.3.5+dfsg-2+deb11u5 | all | < 7.3.18+dfsg-1 | < 7.3.18+dfsg-1
- debian•python2.7
all
- debian•python3.11
< 3.11.2-6+deb12u4
- debian•python3.13
< 3.13.0~rc2-1 | < 3.13.0~rc2-1
- debian•python3.9
< 3.9.2-1+deb11u2
- python software foundation•cpython
< 3.8.20 | ≥ 3.9.0, < 3.9.20 | ≥ 3.10.0, < 3.10.15 | ≥ 3.11.0, < 3.11.10 | ≥ 3.12.0, < 3.12.6 | ≥ 3.13.0a1, < 3.13.0rc2
- python•python
< 3.8.20 | ≥ 3.9.0, < 3.9.20 | ≥ 3.10.0, < 3.10.15 | ≥ 3.11.0, < 3.11.10 | ≥ 3.12.0, < 3.12.6 | 3.13.0:alpha0 | 3.13.0:alpha1 | 3.13.0:alpha2 | 3.13.0:alpha3 | 3.13.0:alpha4 | 3.13.0:alpha5 | 3.13.0:alpha6 | 3.13.0:beta1 | 3.13.0:beta2 | 3.13.0:beta3 | 3.13.0:beta4 | 3.13.0:rc1
- redhat•Cython
< 0:0.29.21-5.module+el8.9.0+19644+d68f775d
- redhat•Cython-debugsource
< 0:0.29.21-5.module+el8.9.0+19644+d68f775d
- redhat•mod_wsgi
< 0:4.7.1-7.module+el8.9.0+19644+d68f775d | < 0:4.7.1-5.module+el8.7.0+16654+645aad7f | < 0:4.7.1-4.module+el8.4.0+9822+20bf1249
- redhat•numpy
< 0:1.19.4-3.module+el8.9.0+19644+d68f775d | < 0:1.19.4-3.module+el8.5.0+12204+54860423 | < 0:1.19.4-2.module+el8.4.0+15042+dc5a279b.1
- redhat•numpy-debugsource
< 0:1.19.4-3.module+el8.9.0+19644+d68f775d | < 0:1.19.4-3.module+el8.5.0+12204+54860423 | < 0:1.19.4-2.module+el8.4.0+15042+dc5a279b.1
- redhat•pybind11
< 0:2.7.1-1.module+el8.9.0+19644+d68f775d
- redhat•pytest
< 0:6.0.2-2.module+el8.9.0+19644+d68f775d
- redhat•python-attrs
< 0:20.3.0-2.module+el8.9.0+19644+d68f775d
- redhat•python-cffi
< 0:1.14.3-2.module+el8.9.0+19644+d68f775d | < 0:1.14.3-2.module+el8.4.0+9822+20bf1249
- redhat•python-cffi-debugsource
< 0:1.14.3-2.module+el8.9.0+19644+d68f775d | < 0:1.14.3-2.module+el8.4.0+9822+20bf1249
- redhat•python-chardet
< 0:3.0.4-19.module+el8.9.0+19644+d68f775d | < 0:3.0.4-19.module+el8.4.0+9822+20bf1249
- redhat•python-cryptography
< 0:3.3.1-3.module+el8.10.0+21271+eccd1d86 | < 0:3.3.1-2.module+el8.4.0+9822+20bf1249
- redhat•python-cryptography-debugsource
< 0:3.3.1-3.module+el8.10.0+21271+eccd1d86 | < 0:3.3.1-2.module+el8.4.0+9822+20bf1249
- redhat•python-idna
< 0:2.10-4.module+el8.10.0+21815+bb024982 | < 0:2.10-3.module+el8.4.0+9822+20bf1249
- redhat•python-iniconfig
< 0:1.1.1-2.module+el8.9.0+19644+d68f775d
- redhat•python-lxml
< 0:4.6.5-1.module+el8.9.0+19644+d68f775d | < 0:4.6.5-1.module+el8.6.0+13933+9cf0c87c | < 0:4.6.2-2.module+el8.4.0+9822+20bf1249
- redhat•python-lxml-debugsource
< 0:4.6.5-1.module+el8.9.0+19644+d68f775d | < 0:4.6.5-1.module+el8.6.0+13933+9cf0c87c | < 0:4.6.2-2.module+el8.4.0+9822+20bf1249
- redhat•python-more-itertools
< 0:8.5.0-2.module+el8.9.0+19644+d68f775d
- redhat•python-packaging
< 0:20.4-4.module+el8.9.0+19644+d68f775d
- redhat•python-pluggy
< 0:0.13.1-3.module+el8.9.0+19644+d68f775d
- redhat•python-ply
< 0:3.11-10.module+el8.9.0+19644+d68f775d | < 0:3.11-10.module+el8.4.0+9822+20bf1249
- redhat•python-psutil
< 0:5.8.0-4.module+el8.9.0+19644+d68f775d | < 0:5.8.0-4.module+el8.4.0+9822+20bf1249
- redhat•python-psutil-debugsource
< 0:5.8.0-4.module+el8.9.0+19644+d68f775d | < 0:5.8.0-4.module+el8.4.0+9822+20bf1249
- redhat•python-psycopg2
< 0:2.8.6-3.module+el8.10.0+21142+453d2b75 | < 0:2.8.6-2.module+el8.4.0+9822+20bf1249
- redhat•python-psycopg2-debugsource
< 0:2.8.6-3.module+el8.10.0+21142+453d2b75 | < 0:2.8.6-2.module+el8.4.0+9822+20bf1249
- redhat•python-py
< 0:1.10.0-1.module+el8.9.0+19644+d68f775d
- redhat•python-pycparser
< 0:2.20-3.module+el8.9.0+19644+d68f775d | < 0:2.20-3.module+el8.4.0+9822+20bf1249
- redhat•python-PyMySQL
< 0:0.10.1-2.module+el8.9.0+19644+d68f775d | < 0:0.10.1-2.module+el8.4.0+9822+20bf1249
- redhat•python-pysocks
< 0:1.7.1-4.module+el8.9.0+19644+d68f775d | < 0:1.7.1-4.module+el8.4.0+9822+20bf1249
- redhat•python-requests
< 0:2.25.0-3.module+el8.9.0+19644+d68f775d | < 0:2.25.0-2.module+el8.4.0+9822+20bf1249
- redhat•python-toml
< 0:0.10.1-5.module+el8.9.0+19644+d68f775d | < 0:0.10.1-5.module+el8.4.0+9822+20bf1249
- redhat•python-unversioned-command
< 0:3.9.10-4.el9_0.6 | < 0:3.9.18-3.el9_4.6 | < 0:3.9.19-8.el9_5.1
- redhat•python-urllib3
< 0:1.25.10-5.module+el8.10.0+20443+f0a692fe | < 0:1.25.10-4.module+el8.5.0+11712+ea2d2be1 | < 0:1.25.10-3.module+el8.4.0+9822+20bf1249
Showing first 50 affected entries in server-rendered view.
References (54)
- https://github.com/python/cpython/pull/121286
- https://github.com/python/cpython/issues/121285
- https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/
- https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06
- https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4
- https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf
- https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373
- https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d
- https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877
- https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4
- http://www.openwall.com/lists/oss-security/2024/09/03/5
- https://security.netapp.com/advisory/ntap-20241018-0007/
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://security-tracker.debian.org/tracker/CVE-2024-6232
- https://access.redhat.com/errata/RHSA-2024:7647
- https://access.redhat.com/security/updates/classification/#moderate
- https://bugzilla.redhat.com/show_bug.cgi?id=2309426
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_7647.json
- https://access.redhat.com/security/cve/CVE-2024-6232
- https://www.cve.org/CVERecord?id=CVE-2024-6232
- https://nvd.nist.gov/vuln/detail/CVE-2024-6232
- https://access.redhat.com/errata/RHSA-2024:8130
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8130.json
- https://access.redhat.com/errata/RHSA-2024:8359
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8359.json
- https://access.redhat.com/errata/RHSA-2024:8374
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8374.json
- https://access.redhat.com/errata/RHSA-2024:8446
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8446.json
- https://access.redhat.com/errata/RHSA-2024:8447
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8447.json
- https://access.redhat.com/errata/RHSA-2024:8490
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8490.json
- https://access.redhat.com/errata/RHSA-2024:8504
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8504.json
- https://access.redhat.com/errata/RHSA-2024:8797
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8797.json
- https://access.redhat.com/errata/RHSA-2024:8836
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8836.json
- https://access.redhat.com/errata/RHSA-2024:8838
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8838.json
- https://access.redhat.com/errata/RHSA-2024:8977
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8977.json
- https://access.redhat.com/errata/RHSA-2024:9450
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9450.json
- https://access.redhat.com/errata/RHSA-2024:9451
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9451.json
- https://access.redhat.com/errata/RHSA-2024:9468
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_9468.json
- https://access.redhat.com/errata/RHSA-2025:1750
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1750.json
- https://security.alpinelinux.org/vuln/CVE-2024-6232
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6232.json
- https://github.com/python/cpython