Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4435

Опубликовано: 03 июн. 2025
Источник: debian
EPSS Низкий

Описание

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.13fixed3.13.4-1package
python3.12unfixedpackage
python3.11removedpackage
python3.11not-affectedbookwormpackage
python3.9not-affectedpackage
python2.7not-affectedpackage
jythonnot-affectedpackage

Примечания

  • https://github.com/python/cpython/issues/135034

  • https://github.com/python/cpython/pull/135037

  • https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/

  • Fixed by: https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a (main)

  • Fixed by: https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a (3.14)

  • Fixed by: https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01 (v3.13.4)

  • Fixed by: https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da (v3.12.11)

  • Got backported to 3.9 in https://github.com/python/cpython/commit/98016f7c92aa4c1232c68bac1ed6646db31782ec (v3.9.17)

  • Got backported to 3.11 in https://github.com/python/cpython/commit/241f2e54a6a2801a1d2022f0fa56309e124866c3 (v3.11.4)

EPSS

Процентиль: 20%
0.00064
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

CVSS3: 7.5
redhat
2 месяца назад

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

CVSS3: 7.5
nvd
2 месяца назад

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

CVSS3: 7.5
github
2 месяца назад

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

EPSS

Процентиль: 20%
0.00064
Низкий