Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-4559

Опубликовано: 28 авг. 2007
Источник: debian
EPSS Критический

Описание

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python2.3removedpackage
python2.4unfixedpackage
python2.5unfixedpackage

Примечания

  • According to upstream this is the intended behaviour for the module.

  • Since this is a library interface to embed Tar functionality into applications

  • it is in order to not provide the full security safety belts one might

  • expect from an enduser application like tar(1). Plus, addressing this would

  • mean to diverge from upstream permanently and could break the behaviour

  • of external apps. Anyone who wants to see this "fixed" should rather file

  • a PEP on an improved tar interface with additional security guarantees

  • provided by design.

  • https://github.com/python/cpython/issues/45385

EPSS

Процентиль: 100%
0.9302
Критический

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 5.5
redhat
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
nvd
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

suse-cvrf
почти 2 года назад

Security update for python311

EPSS

Процентиль: 100%
0.9302
Критический