uv, ZIP Archive Parsing, CVE-2024-37298 (Medium)

Listen to this Post

The vulnerability in uv versions ≤0.9.5 stemmed from two ZIP parsing inconsistencies. First, uv incorrectly processed central directory entries by ignoring their comment fields. This allowed an attacker to craft a malicious ZIP archive where data in the comment field was misinterpreted as a new, valid directory entry, corrupting the extraction process. Second, uv handled filename fields containing null bytes differently from Python’s `zipfile` module. While `zipfile` truncates a filename at the first null byte, uv would skip extracting such files entirely. An attacker could exploit these differentials to create a ZIP archive with a consistent hash that, when processed by different installers, would extract different sets of files, potentially leading to arbitrary code execution during source distribution builds or by placing malicious files in unexpected locations.
Platform: uv
Version: ≤0.9.5
Vulnerability: ZIP Parsing
Severity: Medium
date: 2024-05-23

Prediction: 2024-05-23

What Undercode Say:

uv pip install malicious-package
python -c "import malicious_package"
Malicious zip creation concept
with zipfile.ZipFile('evil.zip', 'w') as zf:
Manipulating central directory comment
Adding a file with a null byte in its name
zf.writestr('good.py\x00evil.py', malicious_code)

How Exploit:

Craft malicious ZIP with comment payloads or null bytes in filenames to create parsing differentials for inconsistent extraction.

Protection from this CVE

Upgrade to uv ≥0.9.6. Avoid installing untrusted packages. Do not set UV_INSECURE_NO_ZIP_VALIDATION=1.

Impact:

Arbitrary code execution during package installation from malicious source distributions. File placement ambiguity.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top