Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Python Tarfile Flaw: 15-Year-Old Risk Risks 350,000 Projects

7.Locks HexConnections Esm H500

Oh cool, a 5,500-day security hole

At least 350,000 open source projects are believed to be potentially vulnerable to exploitation via a Python module flaw that has remained unfixed for 15 years.

On Tuesday, security firm Trellix said its threat researchers had encountered a vulnerability in Python's tarfile module, which provides a way to read and write compressed bundles of files known as tar archives. Initially, the bug hunters thought they'd chanced upon a zero-day.

Your message here