medium severity
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to ALAS2-2020-1483. Package updates are available for Amazon Linux 2 that fix the following vulnerabilities: CVE-2019-20907: In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation. 1856481: CVE-2019-20907 python: infinite loop in the tarfile module via crafted TAR archive
Remediation
Upgrade python
to version or higher.
References
- CVE
- ALAS2-2020-1483
- Snyk ID
- SNYK-AMZN2-PYTHON-609418
- Published
- 02 Sep, 2020