Description
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
Remediation
References
Related Vulnerabilities
WordPress Plugin dsIDXpress IDX Cross-Site Scripting (2.1.0)
MediaWiki Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2021-41800)
WordPress Plugin Solve Media CAPTCHA Cross-Site Request Forgery (1.1.0)
Liferay DXP Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2022-42129)