Oh cool, a 5,500-day security hole . At least 350,000 open source projects are believed to be potentially vulnerable to exploitation via a Python module flaw that has remained unfixed for 15 years. On Tuesday, security firm Trellix said its threat researchers had encountered a vulnerability in Python's tarfile module, which provides a way to read and write compressed bundles of files known as tar archives. Initially, the bug hunters thought they'd chanced upon a zero-day. . It is estimated that around 350,000 open-source initiatives could possibly be at risk of being exploited due to a vulnerability found in Python.. Python Tarfile Vulnerability, Open Source Security, Code Exploitation. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.