Skip to content

[security] Document zlib, gzip, bz2 and tarfile known vulnerabilities #94531

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
vstinner opened this issue Jul 3, 2022 · 2 comments
Closed
Labels
docs Documentation in the Doc dir type-security A security issue

Comments

@vstinner
Copy link
Member

vstinner commented Jul 3, 2022

The zlib, gzip, bz2 and tarfile module of the Python standard library has known vulnerabilities:

I would be nice to mention them in each module documentation and then list them in https://docs.python.org/dev/library/security_warnings.html

@vstinner vstinner added the type-bug An unexpected behavior, bug, or error label Jul 3, 2022
@AlexWaygood AlexWaygood added docs Documentation in the Doc dir type-security A security issue and removed type-bug An unexpected behavior, bug, or error labels Jul 3, 2022
@gpshead
Copy link
Member

gpshead commented Sep 21, 2022

more than 8 years for tarfile... https://nvd.nist.gov/vuln/detail/CVE-2007-4559 is python specific, but the same thing in gnu tar is from 2001...

@vstinner
Copy link
Member Author

I created this issue as a TODO list for myself, but my TODO list of full of more important stuff. Sadly, I failed to find time to work on the documentation. At least, https://docs.python.org/dev/library/security_warnings.html contains a few warnings.

If someone else wants to complete the doc, please go ahead!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
docs Documentation in the Doc dir type-security A security issue
Projects
None yet
Development

No branches or pull requests

3 participants