ELA-1067-1 python3.4 security update

quoted-overlap zipbomb DoS

2024-03-24
Packagepython3.4
Version3.4.2-1+deb8u17 (jessie)
Related CVEs CVE-2024-0450


The zipfile module was vulnerable to “quoted-overlap” zip-bombs in the Python 3 interpreter.



For Debian 8 jessie, these problems have been fixed in version 3.4.2-1+deb8u17.

We recommend that you upgrade your python3.4 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.