Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qpv-486p-2v4h

Опубликовано: 12 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 9.8

Описание

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

EPSS

Процентиль: 6%
0.00164
Низкий

2 Low

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 3.3
ubuntu
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS3: 2.5
redhat
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS3: 3.3
nvd
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

msrc
4 месяца назад

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

CVSS3: 3.3
debian
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00 ...

EPSS

Процентиль: 6%
0.00164
Низкий

2 Low

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20