Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 38

Количество 38

fstec логотип

BDU:2025-06494

около 1 года назад

Уязвимость функции TarFile.extractall() и TarFile.extract() модуля tarfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю записывать произвольные файлы

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250819-06

12 месяцев назад

Уязвимость python3.12

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250819-05

12 месяцев назад

Уязвимость python3.11

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250925-04

10 месяцев назад

Множественные уязвимости python3

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250925-03

10 месяцев назад

Множественные уязвимости python3.10

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250925-02

10 месяцев назад

Множественные уязвимости python3.11

CVSS3: 9.4
EPSS: Низкий
redos логотип

ROS-20250925-01

10 месяцев назад

Множественные уязвимости python3.12

CVSS3: 9.4
EPSS: Низкий
ubuntu логотип

CVE-2025-4517

около 1 года назад

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 9.4
EPSS: Низкий
redhat логотип

CVE-2025-4517

около 1 года назад

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2025-4517

около 1 года назад

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 9.4
EPSS: Низкий
msrc логотип

CVE-2025-4517

5 месяцев назад

Arbitrary writes via tarfile realpath overflow

CVSS3: 9.4
EPSS: Низкий
debian логотип

CVE-2025-4517

около 1 года назад

Allows arbitrary filesystem writes outside the extraction directory du ...

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-6r6c-684h-9j7p

около 1 года назад

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the ...

CVSS3: 9.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02057-1

около 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02050-1

около 1 года назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02049-1

около 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02048-1

около 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02047-1

около 1 года назад

Security update for python310

EPSS: Низкий
rocky логотип

RLSA-2025:10189

10 месяцев назад

Important: python3.12 security update

EPSS: Низкий
rocky логотип

RLSA-2025:10148

10 месяцев назад

Important: python3.11 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-06494

Уязвимость функции TarFile.extractall() и TarFile.extract() модуля tarfile интерпретатора языка программирования Python (CPython), позволяющая нарушителю записывать произвольные файлы

CVSS3: 9.4
1%
Низкий
около 1 года назад
redos логотип
ROS-20250819-06

Уязвимость python3.12

CVSS3: 9.4
1%
Низкий
12 месяцев назад
redos логотип
ROS-20250819-05

Уязвимость python3.11

CVSS3: 9.4
1%
Низкий
12 месяцев назад
redos логотип
ROS-20250925-04

Множественные уязвимости python3

CVSS3: 9.4
10 месяцев назад
redos логотип
ROS-20250925-03

Множественные уязвимости python3.10

CVSS3: 9.4
10 месяцев назад
redos логотип
ROS-20250925-02

Множественные уязвимости python3.11

CVSS3: 9.4
10 месяцев назад
redos логотип
ROS-20250925-01

Множественные уязвимости python3.12

CVSS3: 9.4
10 месяцев назад
ubuntu логотип
CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 9.4
1%
Низкий
около 1 года назад
redhat логотип
CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 7.6
1%
Низкий
около 1 года назад
nvd логотип
CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.

CVSS3: 9.4
1%
Низкий
около 1 года назад
msrc логотип
CVE-2025-4517

Arbitrary writes via tarfile realpath overflow

CVSS3: 9.4
1%
Низкий
5 месяцев назад
debian логотип
CVE-2025-4517

Allows arbitrary filesystem writes outside the extraction directory du ...

CVSS3: 9.4
1%
Низкий
около 1 года назад
github логотип
GHSA-6r6c-684h-9j7p

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or "tar". See the tarfile extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information. Only Python versions 3.12 or later are affected by these vulnerabilities, earlier versions don't include the extraction filter feature. Note that for Python 3.14 or later the default value of filter= changed from "no filtering" to `"data", so if you are relying on this new default behavior then your usage is also affected. Note that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the ...

CVSS3: 9.4
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02057-1

Security update for python311

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02050-1

Security update for python39

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02049-1

Security update for python311

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02048-1

Security update for python312

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02047-1

Security update for python310

около 1 года назад
rocky логотип
RLSA-2025:10189

Important: python3.12 security update

10 месяцев назад
rocky логотип
RLSA-2025:10148

Important: python3.11 security update

10 месяцев назад

Уязвимостей на страницу