CVE-2007-4559
Published Aug 28, 2007
Last updated 8 months ago
Overview
- Description
- Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-22
Social media
- Hype score
- Not currently trending
Vendor comments
- Red HatRed Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=263261 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "230CAC0B-F126-4DE4-B789-3C77CBB31F8D", "versionEndExcluding": "3.6.16" }, { "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5AD617D-8CD2-4DC8-84B1-D3FDF9F85607", "versionEndExcluding": "3.8.17", "versionStartIncluding": "3.7.0" }, { "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0287FC5A-256F-40EE-93D0-2DFFE38BB5A1", "versionEndExcluding": "3.9.17", "versionStartIncluding": "3.9.0" }, { "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AA7FA11-C746-4E69-94C2-18E745D82054", "versionEndExcluding": "3.10.12", "versionStartIncluding": "3.10.0" }, { "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD14A157-FEA9-411F-B338-F1B6F726599D", "versionEndExcluding": "3.11.4", "versionStartIncluding": "3.11.0" } ], "operator": "OR" } ] } ]