K000140251: Python vulnerabilities CVE-2022-48564 and CVE-2022-48566
Discription
Security Advisory Description CVE-2022-48564 read_ints in plistlib_._py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. CVE-2022-48566 An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. Impact There is no impact; F5 products are not affected by these…Read More
References
Back to Main