CVE-2019-20907
—CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
In the news0 stories
No ingested article mentions this CVE yet.