cvelist/2019/20xxx/CVE-2019-20907.json
2023-05-24 21:00:37 +00:00

192 lines
8.1 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2019-20907",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "FEDORA",
"name": "FEDORA-2020-dfb11916cc",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-e9251de272",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CAXHCY4V3LPAAJOBCJ26ISZ4NUXQXTUZ/"
},
{
"refsource": "UBUNTU",
"name": "USN-4428-1",
"url": "https://usn.ubuntu.com/4428-1/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-c3b07cc5c9",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-aab24d3714",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YSL3XWVDMSMKO23HR74AJQ6VEM3C2NTS/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-bb919e575e",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-97d775e649",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TOGKLGTXZLHQQFBVCAPSUDA6DOOJFNRY/"
},
{
"refsource": "GENTOO",
"name": "GLSA-202008-01",
"url": "https://security.gentoo.org/glsa/202008-01"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-826b24c329",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PDKKRXLNVXRF6VGERZSR3OMQR5D5QI6I/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-1ddd5273d6",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-87c0a0a52d",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-efb908b6a8",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-d808fdd597",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-982b2950db",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-c539babb0a",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/"
},
{
"refsource": "MLIST",
"name": "[debian-lts-announce] 20200822 [SECURITY] [DLA 2337-1] python2.7 security update",
"url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1254",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00051.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1257",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00052.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1258",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00053.html"
},
{
"refsource": "SUSE",
"name": "openSUSE-SU-2020:1265",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00056.html"
},
{
"refsource": "FEDORA",
"name": "FEDORA-2020-d30881c970",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/"
},
{
"refsource": "MLIST",
"name": "[debian-lts-announce] 20201119 [SECURITY] [DLA 2456-1] python3.5 security update",
"url": "https://lists.debian.org/debian-lts-announce/2020/11/msg00032.html"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2021.html",
"refsource": "MISC",
"name": "https://www.oracle.com/security-alerts/cpujan2021.html"
},
{
"refsource": "CONFIRM",
"name": "https://bugs.python.org/issue39017",
"url": "https://bugs.python.org/issue39017"
},
{
"refsource": "CONFIRM",
"name": "https://github.com/python/cpython/pull/21454",
"url": "https://github.com/python/cpython/pull/21454"
},
{
"refsource": "CONFIRM",
"name": "https://security.netapp.com/advisory/ntap-20200731-0002/",
"url": "https://security.netapp.com/advisory/ntap-20200731-0002/"
},
{
"refsource": "MLIST",
"name": "[debian-lts-announce] 20230524 [SECURITY] [DLA 3432-1] python2.7 security update",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html"
}
]
}
}