PT-2025-41152 · Python+9 · Python+9
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 2.3
Description
The 'zipfile' module does not validate the ZIP64 End of Central Directory (EOCD) Locator record offset value, leading to potential discrepancies in how ZIP archives are handled compared to other ZIP implementations. Specifically, the module incorrectly assumes the ZIP64 EOCD record's location, potentially allowing crafted ZIP archives to be processed in an unexpected manner.
Recommendations
Update to version 2.3 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Debian
Linuxmint
Python
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu