CVE-2019-9674 PUBLISHED

Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.

EPSS 1.26% · 79.3th percentile

Risk Scores

EPSS Score
1.26%
79.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSpython3.43.4~b1-4ubuntu6, 3.4~b1-5ubuntu2, 3.4~b2-1
Ubuntu:Pro:14.04:LTSpython2.72.7.6-8ubuntu0.6+esm2, 2.7.5-8ubuntu3, 2.7.5-8ubuntu4
Ubuntu:18.04:LTSpython2.72.7.14-2ubuntu2, 2.7.17-1~18.04ubuntu1, 2.7.17-1~18.04
Ubuntu:Pro:22.04:LTSpython2.72.7.18-13, 2.7.18-13ubuntu1.5+esm2, 0
Ubuntu:20.04:LTSpython2.72.7.17-1ubuntu5, 0, 2.7.17~rc1-1
Ubuntu:18.04:LTSpython3.63.6.4-1, 3.6.4-2, 3.6.4-3build1
Ubuntu:16.04:LTSpython3.53.5.2-2ubuntu0~16.04.8, 3.5.2-2ubuntu0~16.04.3, 3.5.2-2ubuntu0~16.04.2
Ubuntu:16.04:LTSpython2.72.7.11-7, 2.7.12-1ubuntu0~16.04.11, 2.7.12-1ubuntu0~16.04.9
Ubuntu:Pro:18.04:LTSpython3.73.7.0~a3-3, 3.7.0~b1-1, 3.7.0~a4-1
Ubuntu:Pro:14.04:LTSpython3.53.5.2-2ubuntu0~16.04.4~14.04.1, 0

Timeline

References

Open in Interactive Console →