---
cve: "CVE-2024-6232"
severity: "HIGH"
cvss: 7.5
epss: "2.2%"
vendor: "Python Software Foundation"
kev: false
exploited: false
published: "2024-09-03 13:15:05"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T05:38:41+02:00"
---

# CVE-2024-6232

> 7.5 HIGH · 🧪 PoC

## Beschreibung

There is a MEDIUM severity vulnerability affecting CPython.





Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 39b2f82717a69dde7212bc39b673b0f55c99e6a3 (Commit)
- 8c3f7946ec848ec16cf28418c0f984ecaa029541 (Commit)

## Referenzen

- <https://github.com/python/cpython/pull/121286>
- <https://github.com/python/cpython/issues/121285>
- <https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/>
- <https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06>
- <https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4>
- <https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf>
- <https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373>
- <https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d>
- <https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877>
- <https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4>
- <http://www.openwall.com/lists/oss-security/2024/09/03/5>
- <https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-6232) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
