Skip to content

Progress on Zip Bomb vulnerability #20

@krnick

Description

@krnick

Hello @vstinner ,

Thank you very much for recording all the issues related to Python security.
I am Junwei Song, the reporter of the zip bomb vulnerability.

This patch does not fix the CPython zipfile library itself. Instead, we improved the documentation with Serhiy and Christian's suggestion to inform users of the problems they might have and the pull request got merged last week.

The link below is the pull request
python/cpython#13378

Also, the improvement of the documentation was
committed in versions 3.8 and 3.9 😄.

Thank you!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions