Количество 33
Количество 33
BDU:2025-09994
Уязвимость интерпретатора языка программирования Python (CPython), связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
ROS-20250925-04
Множественные уязвимости python3
ROS-20250925-03
Множественные уязвимости python3.10
ROS-20250925-02
Множественные уязвимости python3.11
ROS-20250925-01
Множественные уязвимости python3.12
CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
CVE-2025-4435
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
CVE-2025-4435
Tarfile extracts filtered members when errorlevel=0
CVE-2025-4435
When using a TarFile.errorlevel = 0and extracting with a filter the do ...
GHSA-p72v-37h5-753v
When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.
SUSE-SU-2025:02359-1
Security update for python312
SUSE-SU-2025:02767-1
Security update for python313
SUSE-SU-2025:02717-1
Security update for python311
RLSA-2025:10189
Important: python3.12 security update
RLSA-2025:10148
Important: python3.11 security update
RLSA-2025:10140
Important: python3.12 security update
RLSA-2025:10136
Important: python3.9 security update
RLSA-2025:10128
Important: python3 security update
RLSA-2025:10031
Important: python3.12 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-09994 Уязвимость интерпретатора языка программирования Python (CPython), связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
ROS-20250925-04 Множественные уязвимости python3 | CVSS3: 9.4 | 10 месяцев назад | ||
ROS-20250925-03 Множественные уязвимости python3.10 | CVSS3: 9.4 | 10 месяцев назад | ||
ROS-20250925-02 Множественные уязвимости python3.11 | CVSS3: 9.4 | 10 месяцев назад | ||
ROS-20250925-01 Множественные уязвимости python3.12 | CVSS3: 9.4 | 10 месяцев назад | ||
CVE-2025-4435 When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
CVE-2025-4435 When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
CVE-2025-4435 When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
CVE-2025-4435 Tarfile extracts filtered members when errorlevel=0 | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
CVE-2025-4435 When using a TarFile.errorlevel = 0and extracting with a filter the do ... | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-p72v-37h5-753v When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
SUSE-SU-2025:02359-1 Security update for python312 | 10 месяцев назад | |||
SUSE-SU-2025:02767-1 Security update for python313 | 12 месяцев назад | |||
SUSE-SU-2025:02717-1 Security update for python311 | 12 месяцев назад | |||
RLSA-2025:10189 Important: python3.12 security update | 10 месяцев назад | |||
RLSA-2025:10148 Important: python3.11 security update | 10 месяцев назад | |||
RLSA-2025:10140 Important: python3.12 security update | 10 месяцев назад | |||
RLSA-2025:10136 Important: python3.9 security update | 10 месяцев назад | |||
RLSA-2025:10128 Important: python3 security update | 2 месяца назад | |||
RLSA-2025:10031 Important: python3.12 security update | около 1 года назад |
Уязвимостей на страницу