CVE-2022-48564
Summary
| CVE | CVE-2022-48564 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2023-12-15 15:56:00 UTC |
| Description | read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2022-48564 Python Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 3614-1] python3.7 security update |
MLIST |
lists.debian.org |
|
| Issue 42103: [security] DoS (MemError via CPU and RAM exhaustion) when processing malformed Apple Property List files in binary format - Python tracker |
MISC |
bugs.python.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161272 Oracle Enterprise Linux Security Update for python3 (ELSA-2024-0114)
- 199948 Ubuntu Security Notification for Python Vulnerabilities (USN-6513-1)
- 242742 Red Hat Update for python3 (RHSA-2024:0430)
- 242804 Red Hat Update for python3 (RHSA-2024:0586)
- 242885 Red Hat Update for python3 (RHSA-2024:0114)
- 379638 Alibaba Cloud Linux Security Update for python3 (ALINUX3-SA-2024:0040)
- 6000279 Debian Security Update for python3.7 (DLA 3614-1)
- 941537 AlmaLinux Security Update for python3 (ALSA-2024:0114)