DEBIAN-CVE-2024-5569

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 09 Jul 2024, 00:15
Last modified:28 Apr 2026, 20:29

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.2 MEDIUM
3.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2024, 00:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:29
Last Modified
Vulnerability information updated

Description

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the `Path` module in both zipp and zipfile, such as `joinpath`, the overloaded division operator, and `iterdir`. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.

CVSS Metrics

  • v3.0MEDIUMScore: 6.2CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Systems

  • debianpython-zipp

    all | < 1.0.0-6+deb12u1 | < 3.19.2-1 | < 3.19.2-1

References (1)