15-year-old Python bug leaves over 350,000 projects vulnerable

15-year-old Python bug leaves over 350,000 projects vulnerable

Trellix researchers have discovered a bug in the Python programming language that puts hundreds of thousands of software projects at risk. The identified security vulnerability has existed in Python for 15 years.

Help

More than 16 million hryvnias have already been collected for a fighter for the Armed Forces of Ukraine - thanks to the readers who donated 7 million hryvnias

It is noted that the CVE-2007-4559 vulnerability was first discovered back in 2007. It resides in the tarfile module, which is used by Python programs to read and write Tar archives. With its help, attackers can carry out a path traversal attack and overwrite arbitrary files in the system, which can lead to the execution of malicious code. Then the vulnerability was not fixed, but only limited to a warning about the existing risk in the updated documentation. To be fair, there have been no reports of attacks or security threats capable of exploiting CVE-2007-4559.

However, Trellix recently published a vulnerability alert. While analyzing an unrelated vulnerability, the researchers said they had stumbled upon an ancient bug in the tarfile module.

While discussing the issue on the Python bug tracker, the developers once again concluded that CVE-2007-4559 is not a bug: “tarfile.py does nothing wrong,” the developers said, and “there are no known or possible practical exploits.” The official Python documentation has been updated yet again with a warning about the possible dangers associated with extracting archives from untrusted sources.

Well

Frontend distribution

Earn $1800 already in two weeks and learn at the right time

REGISTER!

Frontend distribution

Trellix researchers disagree with this approach and insist that CVE-2007-4559 is indeed a security vulnerability. As evidence, they described and demonstrated a simple exploit exploiting a vulnerability in the Spyder development environment.

Trellix also studied the prevalence of CVE-2007-4559 by analyzing both closed and open source projects. Initially, they found a vulnerability rate of 61% in 257 different code repositories, and after automatically checking and analyzing a larger dataset of 588,840 repositories, this increased to 65%.

Trellix estimates that more than 350,000 projects may be affected by the CVE-2007-4559 vulnerability. And many of these projects are being used by machine learning tools to help developers complete projects faster. The researchers have already created fixes for about 11 thousand projects and intend to continue to work in this direction.

Source: techspot

Related Posts

UK to regulate cryptocurrency memes: illegal advertising

Britain’s financial services regulator has issued guidance to financial services companies and social media influencers who create memes about cryptocurrencies and other investments to regulate them amid…

unofficial renders of the Google Pixel 9 and information about the Pixel 9 Pro XL

The whistleblower @OnLeaks and the site 91mobiles presented the renders of the Google Pixel 9 phone. Four images and a 360° video show a black smartphone with…

Embracer to sell Gearbox (Borderlands) to Take-Two (Rockstar and 2K) for $460 million

Embracer continues to sell off assets – the Swedish gaming holding has just confirmed the sale of The Gearbox Entertainment studio to Take-Two Interactive. The sum is…

photo of the new Xbox X console

The eXputer site managed to get a photo of a new modification of the Microsoft Xbox game console. The source reports that it is a white Xbox…

Israel Deploys Massive Facial Recognition Program in Gaza, – The New York Times

The Technology section is powered by Favbet Tech The images are matched against a database of Palestinians with ties to Hamas. According to The New York Times,…

Twitch has banned chest and buttock broadcasts of gameplay

Twitch has updated its community rules and banned the focus of streams on breasts and buttocks. According to the update, starting March 29, “content that focuses on…

Leave a Reply

Your email address will not be published. Required fields are marked *