Description
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-45624 | An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x. |
Ubuntu USN |
USN-6547-1 | Python vulnerability |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
References
History
Fri, 27 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:python:python:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-03T14:04:01.955Z
Reserved: 2023-08-23T00:00:00.000Z
Link: CVE-2023-41105
Updated: 2024-08-02T18:54:02.969Z
Status : Modified
Published: 2023-08-23T07:15:08.590
Modified: 2024-11-21T08:20:35.710
Link: CVE-2023-41105
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN