Sploitus

CVE-2024-5569

No indexed exploits for CVE-2024-5569 yet

A Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions prior to 3.19.1. The vulnerability is triggered when processing a specially crafted zip file that leads to an infinite loop. This issue also impacts the zipfile module of CPython, as features from the third-party zipp library are later merged into CPython, and the affected code is identical in both projects. The infinite loop can be initiated through the use of functions affecting the `Path` module in both zipp and zipfile, such as `joinpath`, the overloaded division operator, and `iterdir`. Although the infinite loop is not resource exhaustive, it prevents the application from responding. The vulnerability was addressed in version 3.19.1 of jaraco/zipp.

Affected products
Cpython, Debian, Linuxmint, Red Os, Suse, Ubuntu
Fix
Available
CVSS 3.0
6.2 MEDIUM
EPSS
0.2% (15th percentile)
Weakness
CWE-835, CWE-400
NVD status
Deferred
Published
2024-07-09
CVE-2024-5569 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-5569 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-5569 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.