It was discovered that Python incorrectly handled tar archive extraction with the filtering option. An attacker could possibly use this issue to modify files in arbitrary filesystem locations and cause data loss.
{
"binaries": [
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "idle-python3.12"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "libpython3.12-dev"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "libpython3.12-minimal"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "libpython3.12-stdlib"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "libpython3.12-testsuite"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "libpython3.12t64"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-dev"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-examples"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-full"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-minimal"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-nopie"
},
{
"binary_version": "3.12.3-1ubuntu0.7",
"binary_name": "python3.12-venv"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-12718"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4138"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4330"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4435"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4517"
}
],
"ecosystem": "Ubuntu:24.04:LTS"
}
{
"binaries": [
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "idle-python3.13"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "libpython3.13"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "libpython3.13-dev"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "libpython3.13-minimal"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "libpython3.13-stdlib"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "libpython3.13-testsuite"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-dev"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-examples"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-full"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-gdbm"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-minimal"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-nopie"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-tk"
},
{
"binary_version": "3.13.3-1ubuntu0.2",
"binary_name": "python3.13-venv"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-12718"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4138"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4330"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4435"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2025-4517"
}
],
"ecosystem": "Ubuntu:25.04"
}