Skip to main content

Threats Tagged 'cve-2024-6923'

View all threats tagged with 'cve-2024-6923'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-6923

Threats Tagged 'cve-2024-6923'

Click on any threat for detailed analysis and mitigation recommendations

This advisory covers a bug fix and enhancement update for python3.12 on Red Hat Enterprise Linux 10. It addresses multiple security issues including a ReDos vulnerability (CVE-2024-6232) in the tarfile module due to excessive backtracking while parsing header values. The update is provided as a bug fix advisory with no explicit security fixes listed for python3.12 in this release, but it includes references to related CVEs. The update affects various Red Hat Enterprise Linux 10 and CodeReady Linux Builder 10 variants across multiple architectures. No known exploits are reported in the wild. The update is available and should be applied according to Red Hat's guidance.

Join the discussion

Users of service-interconnect 1.5 rhel9 container images are advised to upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory the in Red Hat Container Catalog

Join the discussion

Users of service-interconnect 1.4 LTS rhel9 container images are advised to upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory the in Red Hat Container Catalog

Join the discussion

Users of service-interconnect rhel9 container images are advised to upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory the in Red Hat Container Catalog

Join the discussion

Users of service-interconnect 1.4 LTS rhel9 container images are advised to upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images. You can find images updated by this advisory the in Red Hat Container Catalog

Join the discussion

CVE-2024-6232 is a high severity vulnerability in CPython affecting the tarfile module. It involves a regular expression that allows excessive backtracking during the parsing of TarFile headers, leading to a Regular Expression Denial of Service (ReDoS) when processing specially crafted tar archives. This vulnerability affects multiple Python versions prior to patched releases. Red Hat has issued an important security update addressing this issue in their python3.9 packages for Red Hat Enterprise Linux 9.2 Extended Update Support. A patch is available to remediate the vulnerability.

Join the discussion
0

Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix. Security Fix(es): * cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection (CVE-2024-6923) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

Join the discussion

There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

Join the discussion

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cve-2024-6923
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses