Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.10.12-1~22.04.2", "binary_name": "idle-python3.10" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10-dbg" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10-dev" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10-minimal" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10-stdlib" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "libpython3.10-testsuite" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-dbg" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-dev" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-doc" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-examples" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-full" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-minimal" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-nopie" }, { "binary_version": "3.10.12-1~22.04.2", "binary_name": "python3.10-venv" } ] }