[issue39341] [security] zipfile: ZIP Bomb vulnerability, don't check announced uncompressed size

STINNER Victor report at bugs.python.org
Wed Jan 15 08:18:10 EST 2020


STINNER Victor <vstinner at python.org> added the comment:

> Is this 2.7 only issue? I think it is too late.

I vaguely recall that Christian Heimes wrote something about Python 3 in a private email, but I cannot find this email anymore :-p In case of doubt, I marked Python 3 as affected as well.

----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue39341>
_______________________________________


More information about the Python-bugs-list mailing list