Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-4559

Опубликовано: 24 авг. 2007
Источник: redhat
CVSS3: 5.5
EPSS Высокий

Описание

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

A flaw was found in the Python tarfile module. Extracting a crafted TAR archive with the tarfile.extract or tarfile.extractall functions could lead to a directory traversal vulnerability, resulting in overwrite of arbitrary files.

Отчет

The Red Hat Product Security has rated this issue as having a Moderate security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification. Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

Меры по смягчению последствий

Do not extract archives from untrusted sources with the Python tarfile module. Users of the module should add sanity checks when calling the tarfile.extract or tarfile.extractall functions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pythonOut of support scope
Red Hat Enterprise Linux 7pythonOut of support scope
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8python27:2.7/python2Will not fix
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python3.11-pipFixedRHSA-2023:691414.11.2023
Red Hat Enterprise Linux 8python3.11FixedRHSA-2023:702414.11.2023
Red Hat Enterprise Linux 8python39FixedRHSA-2023:703414.11.2023
Red Hat Enterprise Linux 8python39-develFixedRHSA-2023:703414.11.2023
Red Hat Enterprise Linux 8python38FixedRHSA-2023:705014.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=263261python: tarfile module directory traversal

EPSS

Процентиль: 99%
0.87871
Высокий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
nvd
больше 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractal ...

suse-cvrf
больше 2 лет назад

Security update for python311

EPSS

Процентиль: 99%
0.87871
Высокий

5.5 Medium

CVSS3