Query Regarding CVE-2024-3220
Nandakrishnan P N via Jython-dev <[email protected]> Thu, 20 Feb 2025 05:05:19 +0000
| Newsgroups | gmane.comp.lang.jython.devel |
|---|---|
| Message-ID | <SA1PR15MB45697F621B4252345E6058AAA3C42@SA1PR15MB4569.namprd15.prod.outlook.com> |
--===============6719912196444366460==
Content-Language: en-IN
Content-Type: multipart/alternative;
boundary="_000_SA1PR15MB45697F621B4252345E6058AAA3C42SA1PR15MB4569namp_"
--_000_SA1PR15MB45697F621B4252345E6058AAA3C42SA1PR15MB4569namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
Hello Jython-Dev,
I would like to know regarding the vulnerability of CVE-2024-3220 in jython=
. The description of the vulnerability is as follows:
=93There is a defect in the CPython standard library module =93mimetypes=94=
where on Windows the default list of known file locations are writable mea=
ning other users can create invalid files to cause MemoryError to be raised=
on Python runtime startup or have file extensions be interpreted as the in=
correct file type. This defect is caused by the default locations of Linux =
and macOS platforms (such as =93/etc/mime.types=94) also being used on Wind=
ows, where they are user-writable locations (=93C:\etc\mime.types=94). To w=
ork-around this issue a user can call mimetypes.init() with an empty list (=
=93[]=94) on Windows platforms to avoid using the default list of known fil=
e locations.=94
Link: https://nvd.nist.gov/vuln/detail/CVE-2024-3220
https://access.redhat.com/security/cve/CVE-2024-3220
Can jython be vulnerable to this ? If yes, is there any fix in plan?
From my understanding, this is a low vulnerability and the level of vulnera=
bility depends on how the user use jython. The work around for the issue is=
that, a user can call mimetypes.init() with an empty list. Please share yo=
ur insights.
I=92m new to jython-user group. Please let me know if there is any other w=
ay to communicate these details.
Thanks & Regards
Nandakrishnan P N
Software Developer , IBM
--_000_SA1PR15MB45697F621B4252345E6058AAA3C42SA1PR15MB4569namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable
<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Aptos;
panose-1:2 11 0 4 2 2 2 2 2 4;}
@font-face
{font-family:"Source Sans Pro";
panose-1:2 11 5 3 3 4 3 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#467886;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:11.0pt;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang=3D"EN-IN" link=3D"#467886" vlink=3D"#96607D" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"EN-US">Hello Jython-Dev,<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US">I would like to know regarding =
the vulnerability of CVE-2024-3220 in jython. The description of the vulner=
ability is as follows:<br>
=93</span><span style=3D"font-size:12.5pt;font-family:"Source Sans Pro=
",sans-serif;color:#333333;background:white;mso-ligatures:none;mso-far=
east-language:EN-GB">There is a defect in the CPython standard library modu=
le =93mimetypes=94 where on Windows the default list
of known file locations are writable meaning other users can create invali=
d files to cause MemoryError to be raised on Python runtime startup or have=
file extensions be interpreted as the incorrect file type. This defect is =
caused by the default locations
of Linux and macOS platforms (such as =93/etc/mime.types=94) also being us=
ed on Windows, where they are user-writable locations (=93C:\etc\mime.types=
=94). To work-around this issue a user can call mimetypes.init() with an em=
pty list (=93[]=94) on Windows platforms to
avoid using the default list of known file locations.=94<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">Link:
<a href=3D"https://nvd.nist.gov/vuln/detail/CVE-2024-3220">https://nvd.nist=
.gov/vuln/detail/CVE-2024-3220</a></span><span style=3D"font-size:12.5pt;fo=
nt-family:"Source Sans Pro",sans-serif;background:white;mso-ligat=
ures:none;mso-fareast-language:EN-GB"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:black;background:white;mso-ligatures:n=
one;mso-fareast-language:EN-GB"> &=
nbsp;
<a href=3D"https://access.redhat.com/security/cve/CVE-2024-3220">https://ac=
cess.redhat.com/security/cve/CVE-2024-3220</a></span><span style=3D"font-si=
ze:12.5pt;font-family:"Source Sans Pro",sans-serif;color:#333333;=
background:white;mso-ligatures:none;mso-fareast-language:EN-GB"><o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">Can jython be vulnerable to this ? =
If yes, is there any fix in plan?
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">From my understanding, this is a low vuln=
erability and the level of vulnerability depends
on how the user use jython. The work around for the issue is that, a user =
can call mimetypes.init() with an empty list. Please share your insights.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">I=92m new to jython-user group. Please le=
t me know if there is any other way to communicate
these details. <o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">Thanks & Regards<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">Nandakrishnan P N<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.5pt;font-family:"So=
urce Sans Pro",sans-serif;color:#333333;background:white;mso-ligatures=
:none;mso-fareast-language:EN-GB">Software Developer , IBM</span><span styl=
e=3D"font-size:12.0pt;mso-ligatures:none;mso-fareast-language:EN-GB"><o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p>
</div>
</body>
</html>
--_000_SA1PR15MB45697F621B4252345E6058AAA3C42SA1PR15MB4569namp_--
--===============6719912196444366460==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--===============6719912196444366460==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Jython-dev mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/jython-dev
--===============6719912196444366460==--