Home
LOW: 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:NDefault status
unaffected
Any version before 3.13.10
affected
3.14.0 (python) before 3.14.1
affected
3.15.0a1 (python) before 3.15.0
affected
Description
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Product status
Any version before 3.13.10
3.14.0 (python) before 3.14.1
3.15.0a1 (python) before 3.15.0
References
github.com/python/cpython/pull/119343
github.com/python/cpython/issues/119342
github.com/...ommit/694922cf40aa3a28f898b5f5ee08b71b4922df70
github.com/...ommit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba
github.com/...ommit/b64441e4852383645af5b435411a6f849dd1b4cb
mail.python.org/.../thread/2X5IBCJXRQAZ5PSERLHMSJFBHFR3QM2C/