PT-2025-23610 · Tarfile+10 · Tarfile+10
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
python3.12 versions prior to 3.12.7-1ubuntu2.2
python3.13 versions prior to 3.13.0-1ubuntu0.3
Description
Python incorrectly handles tar archive extraction when using the filtering option. Specifically, when
TarFile.errorlevel is set to 0 during extraction with a filter, the system fails to skip filtered members as documented, extracting them instead. This issue could allow a remote attacker to modify files in arbitrary filesystem locations, potentially leading to data loss or compromising the integrity of protected information.Recommendations
Update python3.12 to version 3.12.7-1ubuntu2.2.
Update python3.13 to version 3.13.0-1ubuntu0.3.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Tarfile
Ubuntu