Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-13462

Опубликовано: 31 мар. 2026
Источник: msrc
EPSS Низкий

Описание

tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

EPSS

Процентиль: 6%
0.00164
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS3: 2.5
redhat
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS3: 3.3
nvd
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

CVSS3: 3.3
debian
5 месяцев назад

The "tarfile" module would still apply normalization of AREGTYPE (\x00 ...

CVSS3: 2.5
redos
около 1 месяца назад

Уязвимость python3.13

EPSS

Процентиль: 6%
0.00164
Низкий