Description
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Remediation
References
Related Vulnerabilities
WordPress Plugin SearchWP Live Ajax Search Directory Traversal (1.6.2)
MyBB CVE-2008-3070 Vulnerability (CVE-2008-3070)
WordPress Plugin Video Comments Webcam Recorder Cross-Site Scripting (1.55)
Oracle Application Server Other Vulnerability (CVE-2002-0566)
WordPress Plugin Booster for WooCommerce Multiple Cross-Site Request Forgery Vulnerabilities (6.0.0)