ALAS2-2020-1483

Affecting python package, versions <2.7.18-1.amzn2.0.2

Report new vulnerabilities
medium severity
Do your applications use this vulnerable package? Test your applications

Overview

Affected versions of this package are vulnerable to ALAS2-2020-1483. Package updates are available for Amazon Linux 2 that fix the following vulnerabilities: CVE-2019-20907: In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation. 1856481: CVE-2019-20907 python: infinite loop in the tarfile module via crafted TAR archive

Remediation

Upgrade python to version or higher.

References

CVE
ALAS2-2020-1483
Snyk ID
SNYK-AMZN2-PYTHON-609418
Published
02 Sep, 2020