![]() |
|
Message-ID: <CAADqWPQEdFXvKV-mgUzrwb=UOF-mC5UUpD51tv=SDpG3rOOQtQ@mail.gmail.com>
Date: Tue, 29 Jul 2025 13:36:15 +0000
From: Seth Larson <seth@...hon.org>
To: Mats Wichmann <mats@...hmann.us>
Cc: oss-security@...ts.openwall.com
Subject: Re: Fwd:[CVE-2025-8194] Cpython Tarfile
infinite loop during parsing with negative member offset
Hello!
Thanks for bringing the formatting issue to our attention, the prose
description renders fine in the Vulnogram UI. Regarding the version range,
I believe that is correct. All Python versions (from 0 to 3.14.0) are
affected by this vulnerability. The patches that have landed in GitHub have
not yet been released. When the patches are included in a release the CVE
will automatically update with the fixed versions.
Hope this helps!
Seth Larson
On Tue, Jul 29, 2025 at 12:50 PM Mats Wichmann <mats@...hmann.us> wrote:
> On 7/28/25 13:55, Alan Coopersmith forwarded a cPython security issue:
>
> some unfortunate glitches here. first, a template failure:
>
> > There is a HIGH severity vulnerability affecting {project}.
>
> second and third:
>
> > Please see the linked CVE ID for the latest information on affected
> > versions:
> >
> > * https://www.cve.org/CVERecord?id=CVE-2025-8194
> The CVE contents suggest nothing is broken:
>
> > affected
>
> > affected from 0 before 3.14.0
>
> (3.14 still being unreleased). But patches for this were backported to
> all supported cPython versions, so the effect must be a bit wider than
> that.
>
>
> And in the cve record itself, the patch suggestion comes out mangled.
> _______________________________________________
> PSRT mailing list -- psrt@...hon.org
> To unsubscribe send an email to psrt-leave@...hon.org
> https://mail.python.org/mailman3//lists/psrt.python.org
> Member address: seth.larson@...ound.org
>
Content of type "text/html" skipped
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.