Skip to content

Commit a8922cf

Browse files
committed
Add news entry for CVE-2024-6232
1 parent 0220b82 commit a8922cf

File tree

1 file changed

+16
-0
lines changed

1 file changed

+16
-0
lines changed

Misc/NEWS.d/2.7.18.11.rst

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,3 +14,19 @@ The list method of TarFile now has the "members" parameter
1414
Various tests were added to check for proper behaviour with SymLinks
1515

1616
Python2 doesn't have pathlib, so those tests are disabled
17+
18+
.. bpo: ?
19+
.. date: 2025-01-20
20+
.. nonce:
21+
.. release date: 2025-01-22
22+
.. section: Core and Builtins
23+
24+
CVE-2024-6232
25+
26+
Remove backtracking when parsing tarfile headers
27+
28+
Python2 doesn't support PAX headers so, for the most part this doesn't affect Python2
29+
30+
Various tests were added from the CVE fix to improve rigour
31+
32+
[3.12] gh-121285: Remove backtracking when parsing tarfile headers (GH-121286) (GH-123543)

0 commit comments

Comments
 (0)