CVE Vulnerabilities

CVE-2024-0450

Asymmetric Resource Consumption (Amplification)

Published: Mar 19, 2024 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was found in the CPython zipfile module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-62.el8_10*
Red Hat Enterprise Linux 8RedHatpython39:3.9-8100020240516111311.d47b87a4*
Red Hat Enterprise Linux 8RedHatpython39-devel:3.9-8100020240516111311.d47b87a4*
Red Hat Enterprise Linux 8RedHatpython3.11-0:3.11.9-1.el8_10*
Red Hat Enterprise Linux 8RedHatpython3.12-0:3.12.3-2.el8_10*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-62.el8_10*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpython3-0:3.6.8-47.el8_6.6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatpython3-0:3.6.8-51.el8_8.6*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.18-3.el9_4.1*
Red Hat Enterprise Linux 9RedHatpython3.12-0:3.12.5-2.el9*
Red Hat Enterprise Linux 9RedHatpython3.11-0:3.11.9-7.el9*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.18-3.el9_4.1*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.4.3-5*
Service Interconnect 1 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.5.3-2*
Python2.7Ubuntuesm-apps/focal*
Python2.7Ubuntuesm-apps/jammy*
Python2.7Ubuntufocal*
Python2.7Ubuntujammy*
Python2.7Ubuntutrusty/esm*
Python3.10Ubuntujammy*
Python3.10Ubuntuupstream*
Python3.11Ubuntuesm-apps/jammy*
Python3.11Ubuntujammy*
Python3.11Ubuntumantic*
Python3.12Ubuntumantic*
Python3.12Ubuntuupstream*
Python3.4Ubuntutrusty/esm*
Python3.5Ubuntuesm-infra-legacy/trusty*
Python3.5Ubuntuesm-infra/xenial*
Python3.5Ubuntutrusty/esm*
Python3.6Ubuntuesm-infra/bionic*
Python3.7Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-infra/focal*
Python3.8Ubuntufocal*
Python3.8Ubuntuupstream*
Python3.9Ubuntuesm-apps/focal*
Python3.9Ubuntufocal*
Python3.9Ubuntuupstream*

Potential Mitigations

References